Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2024-39592
Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.
This
allows an …
S4core
Mitigation only
MEDIUM 6.1
CVE-2024-37174
Custom CSS support option in SAP CRM WebClient
UI does not sufficiently encode user-controlled inputs resulting in Cross-Site
Scripting vulnerability…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.7
CVE-2024-39593
SAP Landscape Management allows an authenticated
user to read confidential data disclosed by the REST Provider Definition
response. Successful exploi…
Landscape Management
Mitigation only
MEDIUM 6.1
CVE-2024-34685
Due to weak encoding of user-controlled input in
SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can
be executed in the a…
Netweaver Knowledge Management And Collaboration \(kmc Cm\)
Mitigation only
MEDIUM 6.1
CVE-2024-37173
Due to insufficient input validation, SAP
CRM WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.3
CVE-2024-28164
SAP NetWeaver AS Java (CAF - Guided Procedures)
allows an unauthenticated user to access non-sensitive information about the
server which would other…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.3
CVE-2024-27898
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe…
Netweaver
Mitigation only
MEDIUM 6.1
CVE-2024-27902
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting i…
Netweaver As Abap
Mitigation only
MEDIUM 5.3
CVE-2024-28163
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…
Netweaver Process Integration
Mitigation only
CRITICAL 9.1
CVE-2024-22127
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.5
CVE-2024-22133
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…
Fiori Front End Server
Mitigation only
MEDIUM 5.3
CVE-2024-25644
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2024-25645
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…
Netweaver Enterprise Portal
No fix yet
MEDIUM 5.3
CVE-2024-27900
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…
Abap Platform
Mitigation only
HIGH 7.5
CVE-2024-24743
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f…
Netweaver Application Server Java
Mitigation only
HIGH 7.4
CVE-2024-25642
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…
Cloud Connector
Mitigation only
HIGH 7.2
CVE-2024-22131
In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…
Abap Platform
Mitigation only
MEDIUM 6.3
CVE-2024-22132
SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…
Ides Ecc
Mitigation only
MEDIUM 6.3
CVE-2024-24739
SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w…
Bank Account Management
Mitigation only
MEDIUM 5.4
CVE-2024-22130
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEB…
Crm Webclient Ui
Mitigation only
MEDIUM 5.3
CVE-2024-24740
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2024-22126
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters b…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2024-22128
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not suf…
Netweaver Business Client For Html
Mitigation only
HIGH 7.5
CVE-2024-22124
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22,…
Netweaver
Mitigation only
HIGH 7.5
CVE-2024-22125
Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access high…
Gui Connector
No fix yet
MEDIUM 5.4
CVE-2024-21738
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vu…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.1
CVE-2024-21737
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers…
Application Interface Framework
Mitigation only
MEDIUM 6.5
CVE-2024-21736
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio…
S\/4hana Finance
Mitigation only
HIGH 7.2
CVE-2024-21735
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization …
Lt Replication Server
Mitigation only
MEDIUM 5.4
CVE-2024-21734
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very …
Marketing
Mitigation only