Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2023-31405
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the …
Netweaver Application Server For Java
Mitigation only
HIGH 8.2
CVE-2023-33991
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-contr…
Ui
Mitigation only
MEDIUM 6.1
CVE-2023-32115
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additio…
Master Data Synchronization
Mitigation only
MEDIUM 6.1
CVE-2023-33985
SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Si…
Netweaver
Mitigation only
MEDIUM 6.1
CVE-2023-33986
SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Si…
Customer Relationship Management Abap
Mitigation only
MEDIUM 5.7
CVE-2023-2827
SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of…
Digital Manufacturing
Mitigation only
MEDIUM 5.4
CVE-2023-33984
SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized …
Netweaver
Mitigation only
CRITICAL 9.1
CVE-2023-30744
In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and…
Netweaver Application Server For Java
Mitigation only
HIGH 7.6
CVE-2023-30740
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…
Businessobjects Business Intelligence
Mitigation only
HIGH 7.5
CVE-2023-32111
In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy serve…
Powerdesigner Proxy
Mitigation only
MEDIUM 6.1
CVE-2023-30741
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to r…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 6.1
CVE-2023-30742
SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 74…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 6.1
CVE-2023-30743
Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedT…
Sapui5
Mitigation only
MEDIUM 6.1
CVE-2023-31406
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to r…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.5
CVE-2023-32112
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SA…
S4core
Mitigation only
MEDIUM 5.4
CVE-2023-31407
SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Script…
Business Planning And Consolidation
Mitigation only
MEDIUM 5.0
CVE-2023-31404
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to …
Businessobjects Business Intelligence
Mitigation only
HIGH 7.2
CVE-2023-28762
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the log…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.9
CVE-2023-28764
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the netwo…
Businessobjects
Mitigation only
MEDIUM 5.4
CVE-2023-29188
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746…
Customer Relationship Management Webclient Ui
Mitigation only
MEDIUM 5.4
CVE-2023-29189
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated a…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 6.7
CVE-2023-29187
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting …
Sapsetup
Mitigation only
MEDIUM 6.5
CVE-2023-29185
SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker auth…
Netweaver As Abap Business Server Pages
Mitigation only
MEDIUM 6.5
CVE-2023-29186EPSS 23%
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrit…
Netweaver
Mitigation only
MEDIUM 5.4
CVE-2023-29112
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS clas…
Application Interface
Mitigation only
MEDIUM 5.4
CVE-2023-29110
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, applicati…
Abap Platform
Mitigation only
CRITICAL 9.8
CVE-2023-27497
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker …
Diagnostics Agent
Mitigation only
CRITICAL 9.8
CVE-2023-28765EPSS 15%
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to…
Businessobjects Business Intelligence
Mitigation only
HIGH 8.7
CVE-2023-26458
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscap…
Landscape Management
Mitigation only
HIGH 8.1
CVE-2023-27267EPSS 14%
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with…
Diagnostics Agent
Mitigation only