Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26106

When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - v…

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26107

When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version …

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26108

When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…

Mitigation only
Fix from $1,600 2022-04-12
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-26109

When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - ver…

Mitigation only
Fix from $1,600 2022-04-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-26105

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated …

Mitigation only
Fix from $1,600 2022-04-12
Innovation Management HIGH 7.5
CVE-2022-27658

Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering…

Mitigation only
Fix from $1,950 2022-03-28
Netweaver Application Server Java MEDIUM 5.3
CVE-2022-26103

Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to …

Mitigation only
Fix from $1,600 2022-03-10
Financial Consolidation MEDIUM 5.3
CVE-2022-26104

SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthor…

Mitigation only
Fix from $1,600 2022-03-10
Netweaver Application Server Abap MEDIUM 5.4
CVE-2022-26102

Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to acc…

Mitigation only
Fix from $1,600 2022-03-10
Sapcar CRITICAL 9.8
CVE-2022-26100

SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacke…

Mitigation only
Fix from $2,300 2022-03-10
Fiori Launchpad MEDIUM 6.1
CVE-2022-26101

Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

No fix yet
Fix from $1,600 2022-03-10
Focused Run MEDIUM 6.1
CVE-2022-24399

The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipar…

No fix yet
Fix from $1,600 2022-03-10
Business Objects Business Intelligence Platform MEDIUM 6.5
CVE-2022-24398

Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat…

No fix yet
Fix from $1,600 2022-03-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-24397

SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-…

Mitigation only
Fix from $1,600 2022-03-10
Simple Diagnostics Agent HIGH 7.8
CVE-2022-24396

The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed v…

Fix: after 1.57
Fix from $1,950 2022-03-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-24395

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2022-03-10
Simple Diagnostics Agent HIGH 7.5
CVE-2022-22547

Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a ran…

Fix: 1.58+
Fix from $1,950 2022-03-10
Businessobjects Web Intelligence MEDIUM 5.4
CVE-2022-22546

Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence…

Mitigation only
Fix from $1,600 2022-02-09
Content Server CRITICAL 10.0
CVE-2022-22536 KEVEPSS 98%

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne…

Mitigation only
Fix from $2,300 2022-02-09
Netweaver Application Server Java CRITICAL 9.8
CVE-2022-22532

In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an u…

Mitigation only
Fix from $2,300 2022-02-09
Solution Manager CRITICAL 9.1
CVE-2022-22544

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents a…

Mitigation only
Fix from $2,300 2022-02-09
Adaptive Server Enterprise HIGH 7.8
CVE-2022-22528

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, u…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Application Server Java HIGH 7.5
CVE-2022-22533

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Application Server Abap HIGH 7.5
CVE-2022-22540

SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute cr…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Abap HIGH 7.5
CVE-2022-22543

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87,…

Mitigation only
Fix from $1,950 2022-02-09
Erp Human Capital Management MEDIUM 6.5
CVE-2022-22535

SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees …

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22537

When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versio…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22538

When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - vers…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22539

When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…

Mitigation only
Fix from $1,600 2022-02-09
S\/4hana MEDIUM 6.5
CVE-2022-22542

S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…

Mitigation only
Fix from $1,600 2022-02-09