Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Commerce Cloud CRITICAL 9.8
CVE-2023-39439

SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphra…

Mitigation only
Fix from $2,300 2023-08-08
Supplier Relationship Management MEDIUM 5.8
CVE-2023-39436

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relati…

Mitigation only
Fix from $1,600 2023-08-08
Business One MEDIUM 5.4
CVE-2023-39437

SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it deliver…

Mitigation only
Fix from $1,600 2023-08-08
Businessobjects Business Intelligence CRITICAL 9.0
CVE-2023-37490

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a …

Mitigation only
Fix from $2,300 2023-08-08
Message Server HIGH 8.8
CVE-2023-37491

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL…

Mitigation only
Fix from $1,950 2023-08-08
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-37492

SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS…

Mitigation only
Fix from $1,600 2023-08-08
Netweaver Process Integration MEDIUM 6.1
CVE-2023-37488

In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, …

Mitigation only
Fix from $1,600 2023-08-08
Business One MEDIUM 5.3
CVE-2023-37487

SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended …

Mitigation only
Fix from $1,600 2023-08-08
Powerdesigner CRITICAL 9.8
CVE-2023-37483

SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back…

Mitigation only
Fix from $2,300 2023-08-08
Commerce Cloud HIGH 7.5
CVE-2023-37486

Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access informatio…

Mitigation only
Fix from $1,950 2023-08-08
Host Agent MEDIUM 5.3
CVE-2023-36926

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c…

Mitigation only
Fix from $1,600 2023-08-08
Powerdesigner MEDIUM 5.3
CVE-2023-37484

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt…

Mitigation only
Fix from $1,600 2023-08-08
Powerdesigner HIGH 7.8
CVE-2023-36923

SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious…

Mitigation only
Fix from $1,950 2023-08-08
Business One HIGH 7.5
CVE-2023-33993

B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network …

Mitigation only
Fix from $1,950 2023-08-08
Netweaver HIGH 8.8
CVE-2023-36922

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arb…

Mitigation only
Fix from $1,950 2023-07-11
Businessobjects Business Intelligence HIGH 7.5
CVE-2023-36917

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to…

Mitigation only
Fix from $1,950 2023-07-11
Netweaver Application Server Abap HIGH 7.4
CVE-2023-35874

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53,…

Mitigation only
Fix from $1,950 2023-07-11
Solution Manager HIGH 7.2
CVE-2023-36921

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics…

Mitigation only
Fix from $1,950 2023-07-11
Solution Manager HIGH 7.2
CVE-2023-36925

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitat…

Mitigation only
Fix from $1,950 2023-07-11
Enable Now MEDIUM 6.1
CVE-2023-36918

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options respons…

Mitigation only
Fix from $1,600 2023-07-11
Enable Now MEDIUM 5.3
CVE-2023-36919

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response heade…

Mitigation only
Fix from $1,600 2023-07-11
Web Dispatcher CRITICAL 9.4
CVE-2023-33987

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBD…

Mitigation only
Fix from $2,300 2023-07-11
Web Dispatcher CRITICAL 9.4
CVE-2023-35871

The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KER…

Mitigation only
Fix from $2,300 2023-07-11
Netweaver Bi Content HIGH 8.1
CVE-2023-33989

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal…

Mitigation only
Fix from $1,950 2023-07-11
S4core HIGH 7.3
CVE-2023-35870

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce…

Mitigation only
Fix from $1,950 2023-07-11
Sql Anywhere HIGH 7.1
CVE-2023-33990

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with …

Mitigation only
Fix from $1,950 2023-07-11
Business Warehouse MEDIUM 6.5
CVE-2023-33992

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, …

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35872

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain funct…

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35873

The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functi…

Mitigation only
Fix from $1,600 2023-07-11
Enable Now MEDIUM 6.1
CVE-2023-33988

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-…

Mitigation only
Fix from $1,600 2023-07-11