Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver Enterprise Portal MEDIUM 6.5
CVE-2023-28761

In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access …

Mitigation only
Fix from $1,600 2023-04-11
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-28763

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-ad…

Mitigation only
Fix from $1,600 2023-04-11
Customer Relationship Management MEDIUM 6.3
CVE-2023-27897

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver MEDIUM 6.1
CVE-2023-27499

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficien…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver As Java For Deploy Service MEDIUM 5.3
CVE-2023-24527

SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity ena…

Mitigation only
Fix from $1,600 2023-04-11
Abap Platform Kernel MEDIUM 5.3
CVE-2023-29108

The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netma…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27501

SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to ex…

Mitigation only
Fix from $2,300 2023-03-14
Solution Manager HIGH 8.8
CVE-2023-27893

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP manag…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap HIGH 8.1
CVE-2023-27500

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this att…

Mitigation only
Fix from $1,950 2023-03-14
Businessobjects Business Intelligence HIGH 7.5
CVE-2023-27896

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application ser…

Mitigation only
Fix from $1,950 2023-03-14
Authenticator MEDIUM 6.5
CVE-2023-27895

SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile dev…

Mitigation only
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2023-27894

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameter…

Mitigation only
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2023-27271

In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the…

Mitigation only
Fix from $1,950 2023-03-14
Host Agent HIGH 7.2
CVE-2023-27498

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service t…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27269

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows a…

Mitigation only
Fix from $2,300 2023-03-14
Netweaver Application Server Abap HIGH 7.4
CVE-2023-26459

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, …

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-27270

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has mult…

Mitigation only
Fix from $1,600 2023-03-14
Content Server MEDIUM 6.1
CVE-2023-26457

SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After …

Mitigation only
Fix from $1,600 2023-03-14
Netweaver Application Server For Java MEDIUM 5.3
CVE-2023-26460

Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities …

Mitigation only
Fix from $1,600 2023-03-14
Netweaver Application Server For Java MEDIUM 5.3
CVE-2023-27268

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacke…

Mitigation only
Fix from $1,600 2023-03-14
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2023-25616

In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection …

Mitigation only
Fix from $1,950 2023-03-14
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2023-25617

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution …

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server For Java HIGH 8.6
CVE-2023-23857

Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and …

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-25618

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has mult…

Mitigation only
Fix from $1,600 2023-03-14
Netweaver Application Server Java MEDIUM 5.3
CVE-2023-24526

SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that requi…

No fix yet
Fix from $1,600 2023-03-14
Netweaver MEDIUM 6.1
CVE-2023-0021

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code …

Mitigation only
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2023-24530

SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be…

Mitigation only
Fix from $2,300 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-25614

SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticate…

Mitigation only
Fix from $1,600 2023-02-14
Host Agent HIGH 8.8
CVE-2023-24523

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22…

Mitigation only
Fix from $1,950 2023-02-14
S\/4hana MEDIUM 6.5
CVE-2023-24524

SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalatio…

Mitigation only
Fix from $1,600 2023-02-14