Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Emarsys Sdk HIGH 7.1
CVE-2023-6542

Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a…

Mitigation only
Fix from $1,950 2023-12-12
Solution Manager MEDIUM 6.4
CVE-2023-49587

SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam…

Mitigation only
Fix from $1,600 2023-12-12
Netweaver Application Server Abap CRITICAL 9.4
CVE-2023-49581

SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential…

Mitigation only
Fix from $2,300 2023-12-12
Graphical User Interface HIGH 7.3
CVE-2023-49580

SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to …

Mitigation only
Fix from $1,950 2023-12-12
Human Capital Management MEDIUM 6.1
CVE-2023-49577

The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled …

Mitigation only
Fix from $1,600 2023-12-12
Master Data Governance MEDIUM 5.3
CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus …

Mitigation only
Fix from $1,600 2023-12-12
Commerce Cloud HIGH 8.1
CVE-2023-42481

In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the for…

Mitigation only
Fix from $1,950 2023-12-12
Business Objects Business Intelligence Platform HIGH 7.6
CVE-2023-42478

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which…

Mitigation only
Fix from $1,950 2023-12-12
Businessobjects Web Intelligence MEDIUM 6.8
CVE-2023-42476

SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents whic…

Mitigation only
Fix from $1,600 2023-12-12
Biller Direct MEDIUM 6.1
CVE-2023-42479

An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scri…

Mitigation only
Fix from $1,600 2023-12-12
Business One HIGH 8.0
CVE-2023-31403

SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any…

Mitigation only
Fix from $1,950 2023-11-14
Netweaver Application Server Abap MEDIUM 5.3
CVE-2023-41366

Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54,…

Mitigation only
Fix from $1,600 2023-11-14
Netweaver Application Server Java MEDIUM 5.3
CVE-2023-42480

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimat…

Mitigation only
Fix from $1,600 2023-11-14
Enable Now Enable Now Consump Del MEDIUM 6.1
CVE-2023-36920

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response heade…

Mitigation only
Fix from $1,600 2023-10-30
Netweaver Application Server Java MEDIUM 6.5
CVE-2023-42477

SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca…

No fix yet
Fix from $1,600 2023-10-10
Powerdesigner HIGH 7.5
CVE-2023-40310

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of ex…

Mitigation only
Fix from $1,950 2023-10-10
S\/4hana MEDIUM 5.4
CVE-2023-42473

S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat…

Mitigation only
Fix from $1,600 2023-10-10
Businessobjects Web Intelligence MEDIUM 5.4
CVE-2023-42474

SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malici…

Mitigation only
Fix from $1,600 2023-10-10
S4core MEDIUM 5.4
CVE-2023-40625

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated …

Mitigation only
Fix from $1,600 2023-09-12
Businessobjects HIGH 7.1
CVE-2023-40623

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and lin…

Mitigation only
Fix from $1,950 2023-09-12
Netweaver Application Server Abap MEDIUM 5.4
CVE-2023-40624

SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702,…

Mitigation only
Fix from $1,600 2023-09-12
Businessobjects Business Intelligence CRITICAL 9.9
CVE-2023-40622

SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attack…

Mitigation only
Fix from $2,300 2023-09-12
Commoncryptolib CRITICAL 9.8
CVE-2023-40309

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated …

Mitigation only
Fix from $2,300 2023-09-12
Powerdesigner MEDIUM 6.3
CVE-2023-40621

SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecti…

Mitigation only
Fix from $1,600 2023-09-12
Businessobjects Business Intelligence Platform HIGH 7.3
CVE-2023-42472

Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows …

Mitigation only
Fix from $1,950 2023-09-12
Commoncryptolib HIGH 7.5
CVE-2023-40308

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a…

Mitigation only
Fix from $1,950 2023-09-12
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2023-37489

Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticat…

Mitigation only
Fix from $1,600 2023-09-12
Netweaver MEDIUM 5.3
CVE-2023-41367

Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain acce…

Mitigation only
Fix from $1,600 2023-09-12
S\/4 Hana MEDIUM 5.3
CVE-2023-41368

The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by …

Mitigation only
Fix from $1,600 2023-09-12
S\/4hana MEDIUM 6.1
CVE-2023-40306

SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…

Mitigation only
Fix from $1,600 2023-09-08