Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-35298 SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerab… Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-09-13 MEDIUM 5.4 CVE-2022-35294 An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downl… Netweaver Application Server Abap Mitigation only Fix from $1,6002022-09-13 CRITICAL 9.1 CVE-2022-35293 Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, a… Enable Now Manager Mitigation only Fix from $2,3002022-08-10 HIGH 8.2 CVE-2022-32245 SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive info… Businessobjects Business Intelligence Mitigation only Fix from $1,9502022-08-10 HIGH 8.1 CVE-2022-35291 Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin … Successfactors Mobile Mitigation only Fix from $1,9502022-07-27 HIGH 8.8 CVE-2022-35228 SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.1 CVE-2022-35225 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the net… Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-07-12 MEDIUM 6.1 CVE-2022-35227 A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote att… Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-07-12 HIGH 8.8 CVE-2022-31593 SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co… Business One Mitigation only Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-32249 Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access… Business One Mitigation only Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-35168 Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the … Business One Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.1 CVE-2022-32247 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated … Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-07-12 MEDIUM 6.1 CVE-2022-35170 SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the net… Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-07-12 MEDIUM 6.1 CVE-2022-35172 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i… Netweaver Enterprise Portal Mitigation only Fix from $1,6002022-07-12 MEDIUM 6.1 CVE-2022-35224 SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Si… Enterprise Portal Mitigation only Fix from $1,6002022-07-12 MEDIUM 6.0 CVE-2022-35169 SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.5 CVE-2022-35171 When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr… 3d Visual Enterprise Viewer Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.4 CVE-2022-31597 Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does n… S\/4hana Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.4 CVE-2022-31598 Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an a… Business Objects Business Intelligence Platform Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.3 CVE-2022-32248 Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or… S\/4hana Mitigation only Fix from $1,6002022-07-12 HIGH 7.8 CVE-2022-31591 SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevate… Businessobjects Bw Publisher Service Mitigation only Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-28771 Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re… Business One License Service Api Mitigation only Fix from $1,9502022-07-12 MEDIUM 6.5 CVE-2022-29619 Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002022-07-12 HIGH 8.8 CVE-2022-31595 SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of pri… Adaptive Server Enterprise Mitigation only Fix from $1,9502022-06-14 HIGH 7.8 CVE-2022-31590 SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root di… Powerdesigner Proxy Mitigation only Fix from $1,9502022-06-14 MEDIUM 6.7 CVE-2022-31594 A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system. Adaptive Server Enterprise No fix yet Fix from $1,6002022-06-14 MEDIUM 6.5 CVE-2022-31589 Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than need… Erp Financial Accounting Mitigation only Fix from $1,6002022-06-14 MEDIUM 6.1 CVE-2022-29618 Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an … Netweaver Development Infrastructure Mitigation only Fix from $1,6002022-06-14 MEDIUM 5.0 CVE-2022-29614 SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7… Host Agent No fix yet Fix from $1,6002022-06-14 CRITICAL 9.8 CVE-2022-27668 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute… Netweaver As Abap No fix yet Fix from $2,3002022-06-14