Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Solution Manager MEDIUM 5.4
CVE-2023-0024

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti…

Mitigation only
Fix from $1,600 2023-02-14
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2023-0022

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by…

Mitigation only
Fix from $1,950 2023-01-10
Bank Account Management MEDIUM 5.7
CVE-2023-0023

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl…

Mitigation only
Fix from $1,600 2023-01-10
Netweaver Application Server Abap CRITICAL 9.8
CVE-2023-0014

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERN…

Mitigation only
Fix from $2,300 2023-01-10
Netweaver Application Server For Java CRITICAL 9.8
CVE-2023-0017EPSS 16%

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use…

Mitigation only
Fix from $2,300 2023-01-10
Business Planning And Consolidation HIGH 8.8
CVE-2023-0016

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL …

Mitigation only
Fix from $1,950 2023-01-10
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2023-0018

Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and…

Mitigation only
Fix from $1,600 2023-01-10
Business Objects Business Intelligence Platform MEDIUM 5.4
CVE-2023-0015

In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type…

Mitigation only
Fix from $1,600 2023-01-10
Host Agent MEDIUM 6.7
CVE-2023-0012

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with…

Mitigation only
Fix from $1,600 2023-01-10
Netweaver Application Server Abap MEDIUM 6.1
CVE-2023-0013

The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABA…

Mitigation only
Fix from $1,600 2023-01-10
Disclosure Management MEDIUM 6.5
CVE-2022-41274

SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d…

Mitigation only
Fix from $1,600 2022-12-13
Contract Lifecycle Manager MEDIUM 6.1
CVE-2022-41273

Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio…

Mitigation only
Fix from $1,600 2022-12-13
Solution Manager MEDIUM 6.1
CVE-2022-41275

In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in …

Mitigation only
Fix from $1,600 2022-12-13
Netweaver Process Integration HIGH 8.6
CVE-2022-41272

An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver P…

Mitigation only
Fix from $1,950 2022-12-13
Netweaver Process Integration CRITICAL 9.4
CVE-2022-41271

An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - vers…

Mitigation only
Fix from $2,300 2022-12-13
Basis HIGH 8.8
CVE-2022-41264

Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow…

Mitigation only
Fix from $1,950 2022-12-13
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2022-41267

SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec…

Mitigation only
Fix from $1,950 2022-12-13
Business Planning And Consolidation HIGH 7.5
CVE-2022-41268

In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CP…

No fix yet
Fix from $1,950 2022-12-13
Commerce Webservices 2.0 MEDIUM 6.1
CVE-2022-41266

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs …

Mitigation only
Fix from $1,600 2022-12-13
Netweaver Application Server Java MEDIUM 6.1
CVE-2022-41262

Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a sc…

Mitigation only
Fix from $1,600 2022-12-12
Solution Manager MEDIUM 5.5
CVE-2022-41261

SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data…

Mitigation only
Fix from $1,600 2022-12-12
Business Objects Business Intelligence Platform MEDIUM 6.0
CVE-2022-31596

Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Busi…

Mitigation only
Fix from $1,600 2022-12-12
Financial Consolidation MEDIUM 6.1
CVE-2022-41260

SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject …

Mitigation only
Fix from $1,600 2022-11-08
Netweaver Application Server Abap HIGH 8.7
CVE-2022-41214

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a …

Mitigation only
Fix from $1,950 2022-11-08
Financial Consolidation MEDIUM 6.5
CVE-2022-41258

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when ru…

Mitigation only
Fix from $1,600 2022-11-08
Sql Anywhere MEDIUM 6.5
CVE-2022-41259

SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashi…

Mitigation only
Fix from $1,600 2022-11-08
3d Visual Enterprise Author HIGH 7.8
CVE-2022-41211

Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and …

Mitigation only
Fix from $1,950 2022-11-08
Financial Consolidation MEDIUM 5.4
CVE-2022-41208

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter curr…

Mitigation only
Fix from $1,600 2022-11-08
Businessobjects Business Intelligence HIGH 8.8
CVE-2022-41203

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can …

Mitigation only
Fix from $1,950 2022-11-08
Gui MEDIUM 6.1
CVE-2022-41205

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr…

Mitigation only
Fix from $1,600 2022-11-08