Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Enterprise Portal MEDIUM 5.4
CVE-2024-47594

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser…

Mitigation only
Fix from $1,600 2024-10-08
Commerce Backoffice MEDIUM 5.4
CVE-2024-45278

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful …

Mitigation only
Fix from $1,600 2024-10-08
S\/4 Hana MEDIUM 5.3
CVE-2024-45282

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property …

Mitigation only
Fix from $1,600 2024-10-08
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2024-37179

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting…

Mitigation only
Fix from $1,600 2024-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.8
CVE-2024-45281

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not d…

Patch available
Fix from $1,600 2024-09-10
Student Life Cycle Management MEDIUM 5.4
CVE-2024-42373

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…

Mitigation only
Fix from $1,600 2024-08-13
Document Builder MEDIUM 5.3
CVE-2024-39591

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo…

Mitigation only
Fix from $1,600 2024-08-13
Bex Web Java Runtime Export Web Service HIGH 8.2
CVE-2024-42374

BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve in…

Mitigation only
Fix from $1,950 2024-08-13
Shared Service Framework MEDIUM 6.5
CVE-2024-42376

SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ…

Mitigation only
Fix from $1,600 2024-08-13
Crm Abap Insights Management MEDIUM 5.0
CVE-2024-41737

SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re…

Mitigation only
Fix from $1,600 2024-08-13
Commerce Backoffice MEDIUM 5.4
CVE-2024-41735

SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact…

Mitigation only
Fix from $1,600 2024-08-13
Business Objects Business Intelligence Platform CRITICAL 9.8
CVE-2024-41730EPSS 76%

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo…

Mitigation only
Fix from $2,300 2024-08-13
Netweaver Application Server Abap MEDIUM 5.4
CVE-2024-41732

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t…

Mitigation only
Fix from $1,600 2024-08-13
Commerce MEDIUM 5.3
CVE-2024-41733

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear…

Mitigation only
Fix from $1,600 2024-08-13
Commerce Cloud CRITICAL 9.1
CVE-2024-33003

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number…

Mitigation only
Fix from $2,300 2024-08-13
Netweaver Abap MEDIUM 6.3
CVE-2024-33005

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)…

Mitigation only
Fix from $1,600 2024-08-13
Business Warehouse MEDIUM 6.1
CVE-2024-39594

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cro…

Patch available
Fix from $1,600 2024-07-09
Business Warehouse MEDIUM 5.4
CVE-2024-39595

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-…

Patch available
Fix from $1,600 2024-07-09
Sap Basis MEDIUM 5.3
CVE-2024-37180

Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with…

Patch available
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.5
CVE-2024-37175

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a…

Mitigation only
Fix from $1,600 2024-07-09
S4core MEDIUM 5.4
CVE-2024-37172

SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o…

Mitigation only
Fix from $1,600 2024-07-09
Saptmui MEDIUM 5.0
CVE-2024-37171

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl…

Mitigation only
Fix from $1,600 2024-07-09
Business Workflow MEDIUM 5.0
CVE-2024-34689

WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd HIGH 7.7
CVE-2024-39598

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin…

Mitigation only
Fix from $1,950 2024-07-09
S4core MEDIUM 6.5
CVE-2024-39592

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an …

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.1
CVE-2024-37174

Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability…

Mitigation only
Fix from $1,600 2024-07-09
Landscape Management MEDIUM 5.7
CVE-2024-39593

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploi…

Mitigation only
Fix from $1,600 2024-07-09
Netweaver Knowledge Management And Collaboration \(kmc Cm\) MEDIUM 6.1
CVE-2024-34685

Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the a…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd MEDIUM 6.1
CVE-2024-37173

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script…

Mitigation only
Fix from $1,600 2024-07-09
Bw\/4hana MEDIUM 5.4
CVE-2024-37176

SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by ex…

Patch available
Fix from $1,600 2024-06-11