Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

S4core MEDIUM 6.5
CVE-2024-39592

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an …

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.1
CVE-2024-37174

Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability…

Mitigation only
Fix from $1,600 2024-07-09
Landscape Management MEDIUM 5.7
CVE-2024-39593

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploi…

Mitigation only
Fix from $1,600 2024-07-09
Netweaver Knowledge Management And Collaboration \(kmc Cm\) MEDIUM 6.1
CVE-2024-34685

Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the a…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.1
CVE-2024-37173

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script…

Mitigation only
Fix from $1,600 2024-07-09
Netweaver Application Server Java MEDIUM 5.3
CVE-2024-28164

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would other…

Mitigation only
Fix from $1,600 2024-06-11
Netweaver MEDIUM 5.3
CVE-2024-27898

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe…

Mitigation only
Fix from $1,600 2024-04-09
Netweaver As Abap MEDIUM 6.1
CVE-2024-27902

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Process Integration MEDIUM 5.3
CVE-2024-28163

Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Application Server Java CRITICAL 9.1
CVE-2024-22127

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially …

Mitigation only
Fix from $2,300 2024-03-12
Fiori Front End Server MEDIUM 6.5
CVE-2024-22133

SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver MEDIUM 5.3
CVE-2024-25644

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Enterprise Portal MEDIUM 5.3
CVE-2024-25645

Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…

No fix yet
Fix from $1,600 2024-03-12
Abap Platform MEDIUM 5.3
CVE-2024-27900

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Application Server Java HIGH 7.5
CVE-2024-24743

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f…

Mitigation only
Fix from $1,950 2024-02-13
Cloud Connector HIGH 7.4
CVE-2024-25642

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…

Mitigation only
Fix from $1,950 2024-02-13
Abap Platform HIGH 7.2
CVE-2024-22131

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…

Mitigation only
Fix from $1,950 2024-02-13
Ides Ecc MEDIUM 6.3
CVE-2024-22132

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…

Mitigation only
Fix from $1,600 2024-02-13
Bank Account Management MEDIUM 6.3
CVE-2024-24739

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w…

Mitigation only
Fix from $1,600 2024-02-13
Crm Webclient Ui MEDIUM 5.4
CVE-2024-22130

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEB…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Application Server Abap MEDIUM 5.3
CVE-2024-24740

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Application Server Java MEDIUM 6.1
CVE-2024-22126

The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters b…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Business Client For Html MEDIUM 6.1
CVE-2024-22128

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not suf…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver HIGH 7.5
CVE-2024-22124

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22,…

Mitigation only
Fix from $1,950 2024-01-09
Gui Connector HIGH 7.5
CVE-2024-22125

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access high…

No fix yet
Fix from $1,950 2024-01-09
Netweaver Application Server Abap MEDIUM 5.4
CVE-2024-21738

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vu…

Mitigation only
Fix from $1,600 2024-01-09
Application Interface Framework CRITICAL 9.1
CVE-2024-21737

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers…

Mitigation only
Fix from $2,300 2024-01-09
S\/4hana Finance MEDIUM 6.5
CVE-2024-21736

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio…

Mitigation only
Fix from $1,600 2024-01-09
Lt Replication Server HIGH 7.2
CVE-2024-21735

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization …

Mitigation only
Fix from $1,950 2024-01-09
Marketing MEDIUM 5.4
CVE-2024-21734

SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very …

Mitigation only
Fix from $1,600 2024-01-09