Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2023-24528
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigu…
Fiori
Mitigation only
MEDIUM 6.1
CVE-2023-23859
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to c…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2023-23860
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to c…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2023-24521
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, …
Netweaver As Abap Business Server Pages
Mitigation only
MEDIUM 6.1
CVE-2023-24522
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated u…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2023-24529
Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 7…
Netweaver As Abap Business Server Pages
Mitigation only
MEDIUM 5.4
CVE-2023-24525
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site S…
Customer Relationship Management Webclient Ui
Mitigation only
MEDIUM 6.1
CVE-2023-23852
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) …
Solution Manager
Mitigation only
MEDIUM 6.1
CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2023-23858
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, a…
Netweaver Application Server Abap
No fix yet
MEDIUM 5.4
CVE-2023-0025
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti…
Solution Manager
Mitigation only
MEDIUM 5.4
CVE-2023-23851
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)…
Business Planning And Consolidation
Mitigation only
MEDIUM 5.4
CVE-2023-23854
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorizati…
Netweaver Application Server Abap
Mitigation only
MEDIUM 5.4
CVE-2023-23855
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A succ…
Solution Manager
No fix yet
MEDIUM 5.4
CVE-2023-23856
In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the h…
Business Objects Business Intelligence Platform
Mitigation only
HIGH 7.1
CVE-2023-0020
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2023-0019
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled funct…
Grc Process Control
Mitigation only
MEDIUM 5.4
CVE-2023-0024
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti…
Solution Manager
Mitigation only
HIGH 8.8
CVE-2023-0022
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.7
CVE-2023-0023
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl…
Bank Account Management
Mitigation only
CRITICAL 9.8
CVE-2023-0014
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERN…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.8
CVE-2023-0017EPSS 16%
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use…
Netweaver Application Server For Java
Mitigation only
HIGH 8.8
CVE-2023-0016
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL …
Business Planning And Consolidation
Mitigation only
MEDIUM 6.1
CVE-2023-0018
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2023-0015
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type…
Business Objects Business Intelligence Platform
Mitigation only
MEDIUM 6.7
CVE-2023-0012
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with…
Host Agent
Mitigation only
MEDIUM 6.1
CVE-2023-0013
The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABA…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.5
CVE-2022-41274
SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d…
Disclosure Management
Mitigation only
MEDIUM 6.1
CVE-2022-41273
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio…
Contract Lifecycle Manager
Mitigation only
MEDIUM 6.1
CVE-2022-41275
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in …
Solution Manager
Mitigation only