Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Java HIGH 7.5
CVE-2024-34688

Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, whic…

Patch available
Fix from $1,950 2024-06-11
S\/4 Hana MEDIUM 6.5
CVE-2024-34691

Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalati…

Patch available
Fix from $1,600 2024-06-11
Customer Relationship Management Webclient Ui MEDIUM 6.1
CVE-2024-34686

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. Wh…

Patch available
Fix from $1,600 2024-06-11
Student Life Cycle Management MEDIUM 5.4
CVE-2024-34690

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…

Patch available
Fix from $1,600 2024-06-11
Netweaver Application Server Abap MEDIUM 6.5
CVE-2024-33001

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of th…

Patch available
Fix from $1,600 2024-06-11
Document Builder MEDIUM 6.5
CVE-2024-34683

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to a…

Patch available
Fix from $1,600 2024-06-11
Businessobjects Business Intelligence Platform MEDIUM 6.0
CVE-2024-34684

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local serv…

Patch available
Fix from $1,600 2024-06-11
Netweaver Application Server Java MEDIUM 5.3
CVE-2024-28164

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would other…

Mitigation only
Fix from $1,600 2024-06-11
Sap Basis CRITICAL 9.0
CVE-2024-34687

SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS…

Patch available
Fix from $2,300 2024-05-14
Businessobjects Business Intelligence Platform CRITICAL 9.3
CVE-2024-28165

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument UR…

Patch available
Fix from $2,300 2024-05-14
Businessobjects Web Intelligence MEDIUM 6.5
CVE-2024-25646

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system informati…

Patch available
Fix from $1,600 2024-04-09
Netweaver MEDIUM 5.3
CVE-2024-27898

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe…

Mitigation only
Fix from $1,600 2024-04-09
Netweaver As Abap MEDIUM 6.1
CVE-2024-27902

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Process Integration MEDIUM 5.3
CVE-2024-28163

Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Application Server Java CRITICAL 9.1
CVE-2024-22127

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially …

Mitigation only
Fix from $2,300 2024-03-12
Fiori Front End Server MEDIUM 6.5
CVE-2024-22133

SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver MEDIUM 5.3
CVE-2024-25644

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Enterprise Portal MEDIUM 5.3
CVE-2024-25645

Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…

No fix yet
Fix from $1,600 2024-03-12
Abap Platform MEDIUM 5.3
CVE-2024-27900

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…

Mitigation only
Fix from $1,600 2024-03-12
Companion HIGH 7.6
CVE-2024-22129

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user …

Fix: 3.1.38+
Fix from $1,950 2024-02-13
Netweaver Application Server Java HIGH 7.5
CVE-2024-24743

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f…

Mitigation only
Fix from $1,950 2024-02-13
Cloud Connector HIGH 7.4
CVE-2024-25642

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…

Mitigation only
Fix from $1,950 2024-02-13
Abap Platform HIGH 7.2
CVE-2024-22131

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…

Mitigation only
Fix from $1,950 2024-02-13
Ides Ecc MEDIUM 6.3
CVE-2024-22132

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…

Mitigation only
Fix from $1,600 2024-02-13
Bank Account Management MEDIUM 6.3
CVE-2024-24739

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w…

Mitigation only
Fix from $1,600 2024-02-13
Crm Webclient Ui MEDIUM 5.4
CVE-2024-22130

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEB…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Application Server Abap MEDIUM 5.3
CVE-2024-24740

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Application Server Java MEDIUM 6.1
CVE-2024-22126

The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters b…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver Business Client For Html MEDIUM 6.1
CVE-2024-22128

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not suf…

Mitigation only
Fix from $1,600 2024-02-13
Netweaver HIGH 7.5
CVE-2024-22124

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22,…

Mitigation only
Fix from $1,950 2024-01-09