Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35298

SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerab…

Mitigation only
Fix from $1,600 2022-09-13
Netweaver Application Server Abap MEDIUM 5.4
CVE-2022-35294

An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downl…

Mitigation only
Fix from $1,600 2022-09-13
Enable Now Manager CRITICAL 9.1
CVE-2022-35293

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, a…

Mitigation only
Fix from $2,300 2022-08-10
Authenticator HIGH 7.5
CVE-2022-35290

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

Fix: 1.2.17+
Fix from $1,950 2022-08-10
Businessobjects Business Intelligence HIGH 8.2
CVE-2022-32245

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive info…

Mitigation only
Fix from $1,950 2022-08-10
Successfactors Mobile HIGH 8.1
CVE-2022-35291

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin …

Mitigation only
Fix from $1,950 2022-07-27
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2022-35228

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c…

Mitigation only
Fix from $1,950 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35225

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the net…

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35227

A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote att…

Mitigation only
Fix from $1,600 2022-07-12
Business One HIGH 8.8
CVE-2022-31593

SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co…

Mitigation only
Fix from $1,950 2022-07-12
Business One HIGH 7.5
CVE-2022-32249

Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access…

Mitigation only
Fix from $1,950 2022-07-12
Business One HIGH 7.5
CVE-2022-35168

Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the …

Mitigation only
Fix from $1,950 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-32247

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated …

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35170

SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the net…

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35172

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2022-07-12
Enterprise Portal MEDIUM 6.1
CVE-2022-35224

SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Si…

Mitigation only
Fix from $1,600 2022-07-12
Businessobjects Business Intelligence Platform MEDIUM 6.0
CVE-2022-35169

SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR …

Mitigation only
Fix from $1,600 2022-07-12
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-35171

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…

Mitigation only
Fix from $1,600 2022-07-12
S\/4hana MEDIUM 5.4
CVE-2022-31597

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does n…

Mitigation only
Fix from $1,600 2022-07-12
Business Objects Business Intelligence Platform MEDIUM 5.4
CVE-2022-31598

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an a…

Mitigation only
Fix from $1,600 2022-07-12
S\/4hana MEDIUM 5.3
CVE-2022-32248

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or…

Mitigation only
Fix from $1,600 2022-07-12
Businessobjects Bw Publisher Service HIGH 7.8
CVE-2022-31591

SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevate…

Mitigation only
Fix from $1,950 2022-07-12
Business One License Service Api HIGH 7.5
CVE-2022-28771

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re…

Mitigation only
Fix from $1,950 2022-07-12
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2022-29619

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify …

Mitigation only
Fix from $1,600 2022-07-12
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32240

When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the a…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32241

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, …

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32242

When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the applicat…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32243

When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the …

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32238

When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the a…

Fix: after 9.0
Fix from $1,600 2022-06-14
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-32239

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…

Fix: after 9.0
Fix from $1,600 2022-06-14