Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Fiori MEDIUM 6.5
CVE-2023-24528

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigu…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-23859

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to c…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-23860

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to c…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2023-24521

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, …

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-24522

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated u…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2023-24529

Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 7…

Mitigation only
Fix from $1,600 2023-02-14
Customer Relationship Management Webclient Ui MEDIUM 5.4
CVE-2023-24525

SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site S…

Mitigation only
Fix from $1,600 2023-02-14
Solution Manager MEDIUM 6.1
CVE-2023-23852

SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) …

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-23853

An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-23858

Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, a…

No fix yet
Fix from $1,600 2023-02-14
Solution Manager MEDIUM 5.4
CVE-2023-0025

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti…

Mitigation only
Fix from $1,600 2023-02-14
Business Planning And Consolidation MEDIUM 5.4
CVE-2023-23851

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)…

Mitigation only
Fix from $1,600 2023-02-14
Netweaver Application Server Abap MEDIUM 5.4
CVE-2023-23854

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorizati…

Mitigation only
Fix from $1,600 2023-02-14
Solution Manager MEDIUM 5.4
CVE-2023-23855

SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A succ…

No fix yet
Fix from $1,600 2023-02-14
Business Objects Business Intelligence Platform MEDIUM 5.4
CVE-2023-23856

In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the h…

Mitigation only
Fix from $1,600 2023-02-14
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2023-0020

SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…

Mitigation only
Fix from $1,950 2023-02-14
Grc Process Control MEDIUM 6.5
CVE-2023-0019

In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled funct…

Mitigation only
Fix from $1,600 2023-02-14
Solution Manager MEDIUM 5.4
CVE-2023-0024

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti…

Mitigation only
Fix from $1,600 2023-02-14
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2023-0022

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by…

Mitigation only
Fix from $1,950 2023-01-10
Bank Account Management MEDIUM 5.7
CVE-2023-0023

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl…

Mitigation only
Fix from $1,600 2023-01-10
Netweaver Application Server Abap CRITICAL 9.8
CVE-2023-0014

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERN…

Mitigation only
Fix from $2,300 2023-01-10
Netweaver Application Server For Java CRITICAL 9.8
CVE-2023-0017EPSS 16%

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use…

Mitigation only
Fix from $2,300 2023-01-10
Business Planning And Consolidation HIGH 8.8
CVE-2023-0016

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL …

Mitigation only
Fix from $1,950 2023-01-10
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2023-0018

Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and…

Mitigation only
Fix from $1,600 2023-01-10
Business Objects Business Intelligence Platform MEDIUM 5.4
CVE-2023-0015

In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type…

Mitigation only
Fix from $1,600 2023-01-10
Host Agent MEDIUM 6.7
CVE-2023-0012

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with…

Mitigation only
Fix from $1,600 2023-01-10
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-0013

The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABA…

Mitigation only
Fix from $1,600 2023-01-10
Disclosure Management MEDIUM 6.5
CVE-2022-41274

SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d…

Mitigation only
Fix from $1,600 2022-12-13
Contract Lifecycle Manager MEDIUM 6.1
CVE-2022-41273

Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio…

Mitigation only
Fix from $1,600 2022-12-13
Solution Manager MEDIUM 6.1
CVE-2022-41275

In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in …

Mitigation only
Fix from $1,600 2022-12-13