Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Abap Platform Kernel HIGH 8.1
CVE-2021-40501

SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul…

Mitigation only
Fix from $1,950 2021-11-10
Netweaver Application Server Abap CRITICAL 9.8
CVE-2021-40499

Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…

Mitigation only
Fix from $2,300 2021-10-12
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2021-40500

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v…

Mitigation only
Fix from $1,950 2021-10-12
Netweaver Abap MEDIUM 5.3
CVE-2021-40495

There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 75…

Mitigation only
Fix from $1,600 2021-10-12
Businessobjects Analysis MEDIUM 5.3
CVE-2021-40497

SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive da…

Mitigation only
Fix from $1,600 2021-10-12
Business One CRITICAL 9.8
CVE-2021-38180

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during…

Mitigation only
Fix from $2,300 2021-10-12
Netweaver Abap HIGH 8.8
CVE-2021-38178

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, …

Mitigation only
Fix from $1,950 2021-10-12
Netweaver Abap HIGH 7.5
CVE-2021-38181

SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent leg…

Mitigation only
Fix from $1,950 2021-10-12
Netweaver MEDIUM 6.1
CVE-2021-38183

SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to…

Mitigation only
Fix from $1,600 2021-10-12
Dmis CRITICAL 9.1
CVE-2021-33701

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 202…

No fix yet
Fix from $2,300 2021-09-15
Landscape Transformation HIGH 8.8
CVE-2021-38176

Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution…

Mitigation only
Fix from $1,950 2021-09-14
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2021-38174

When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becom…

Mitigation only
Fix from $1,600 2021-09-14
Analysis For Microsoft Office MEDIUM 6.5
CVE-2021-38175

SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the network, and gather or chang…

Mitigation only
Fix from $1,600 2021-09-14
Netweaver Application Server Java CRITICAL 9.8
CVE-2021-37535

SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization…

Mitigation only
Fix from $2,300 2021-09-14
Web Dispatcher CRITICAL 9.4
CVE-2021-38162

SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53…

No fix yet
Fix from $2,300 2021-09-14
Netweaver Knowledge Management Xml Forms HIGH 8.8
CVE-2021-37531

SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-adminis…

No fix yet
Fix from $1,950 2021-09-14
Netweaver HIGH 8.8
CVE-2021-38163 KEVEPSS 36%

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user…

Mitigation only
Fix from $1,950 2021-09-14
Business Client MEDIUM 6.5
CVE-2021-38150

When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business …

Mitigation only
Fix from $1,600 2021-09-14
Erp Financial Accounting MEDIUM 5.4
CVE-2021-38164

SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE …

Mitigation only
Fix from $1,600 2021-09-14
Business One MEDIUM 6.5
CVE-2021-33685

SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of t…

Mitigation only
Fix from $1,600 2021-09-14
Contact Center MEDIUM 6.1
CVE-2021-33675

Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a…

Mitigation only
Fix from $1,600 2021-09-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2021-33679

The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while cre…

Mitigation only
Fix from $1,600 2021-09-14
Business One MEDIUM 5.3
CVE-2021-33686

Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but…

No fix yet
Fix from $1,600 2021-09-14
Contact Center CRITICAL 9.6
CVE-2021-33672

Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message…

Mitigation only
Fix from $2,300 2021-09-14
Contact Center MEDIUM 6.1
CVE-2021-33673

Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an a…

Mitigation only
Fix from $1,600 2021-09-14
Contact Center MEDIUM 6.1
CVE-2021-33674

Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a…

Mitigation only
Fix from $1,600 2021-09-14
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2021-33703

Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker ca…

No fix yet
Fix from $1,600 2021-08-10
Netweaver Knowledge Management MEDIUM 6.1
CVE-2021-33707

SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a…

No fix yet
Fix from $1,600 2021-08-10
Fiori Client MEDIUM 6.5
CVE-2021-33699

Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml wit…

Mitigation only
Fix from $1,600 2021-08-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2021-33702

Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data.…

No fix yet
Fix from $1,600 2021-08-10