Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver MEDIUM 6.1
CVE-2022-22534

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user …

Mitigation only
Fix from $1,600 2022-02-09
S\/4hana HIGH 8.1
CVE-2022-22530

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…

Mitigation only
Fix from $1,950 2022-01-14
S\/4hana HIGH 8.1
CVE-2022-22531

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…

Mitigation only
Fix from $1,950 2022-01-14
Enterprise Threat Detection MEDIUM 6.1
CVE-2022-22529

SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker p…

Mitigation only
Fix from $1,600 2022-01-14
Business One MEDIUM 5.5
CVE-2021-44234

SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos…

Mitigation only
Fix from $1,600 2022-01-14
Commerce CRITICAL 9.8
CVE-2021-42064

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce -…

Mitigation only
Fix from $2,300 2021-12-14
Abap Platform CRITICAL 9.8
CVE-2021-44231

Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…

Mitigation only
Fix from $2,300 2021-12-14
Access Control HIGH 8.8
CVE-2021-44233

SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c…

Mitigation only
Fix from $1,950 2021-12-14
Saf T Framework HIGH 7.7
CVE-2021-44232

SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to ful…

Mitigation only
Fix from $1,950 2021-12-14
Netweaver Application Server Abap MEDIUM 6.7
CVE-2021-44235

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow a…

Mitigation only
Fix from $1,600 2021-12-14
Knowledge Warehouse MEDIUM 6.1
CVE-2021-42063EPSS 22%

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component with…

No fix yet
Fix from $1,600 2021-12-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2021-42061

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2021-12-14
Commerce HIGH 8.8
CVE-2021-40502

SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es…

Mitigation only
Fix from $1,950 2021-11-10
Abap Platform Kernel HIGH 8.1
CVE-2021-40501

SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul…

Mitigation only
Fix from $1,950 2021-11-10
Gui For Windows HIGH 7.8
CVE-2021-40503

An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient priv…

Fix: 7.60+
Fix from $1,950 2021-11-10
Cloud Sdk MEDIUM 5.9
CVE-2021-41251

@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a…

Fix: 1.52.0+
Fix from $1,600 2021-11-05
Netweaver Application Server Abap CRITICAL 9.8
CVE-2021-40499

Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…

Mitigation only
Fix from $2,300 2021-10-12
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2021-40500

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v…

Mitigation only
Fix from $1,950 2021-10-12
Successfactors Mobile MEDIUM 5.5
CVE-2021-40498

A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prev…

Fix: 2108+
Fix from $1,600 2021-10-12
Netweaver Abap MEDIUM 5.3
CVE-2021-40495

There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 75…

Mitigation only
Fix from $1,600 2021-10-12
Businessobjects Analysis MEDIUM 5.3
CVE-2021-40497

SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive da…

Mitigation only
Fix from $1,600 2021-10-12
Business One CRITICAL 9.8
CVE-2021-38180

SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during…

Mitigation only
Fix from $2,300 2021-10-12
Netweaver Abap HIGH 8.8
CVE-2021-38178

The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, …

Mitigation only
Fix from $1,950 2021-10-12
Netweaver Abap HIGH 7.5
CVE-2021-38181

SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent leg…

Mitigation only
Fix from $1,950 2021-10-12
Netweaver MEDIUM 6.1
CVE-2021-38183

SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to…

Mitigation only
Fix from $1,600 2021-10-12
Netweaver Development Infrastructure CRITICAL 9.9
CVE-2021-33690EPSS 68%

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -…

Patch available
Fix from $2,300 2021-09-15
Cloud Connector CRITICAL 9.1
CVE-2021-33695

Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

Patch available
Fix from $2,300 2021-09-15
Dmis CRITICAL 9.1
CVE-2021-33701

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 202…

No fix yet
Fix from $2,300 2021-09-15
Business One HIGH 8.8
CVE-2021-33698

SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file…

Patch available
Fix from $1,950 2021-09-15
Business One HIGH 8.8
CVE-2021-33704

The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte…

Patch available
Fix from $1,950 2021-09-15