Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gui Connector HIGH 7.5
CVE-2024-22125

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access high…

No fix yet
Fix from $1,950 2024-01-09
Netweaver Application Server Abap MEDIUM 5.4
CVE-2024-21738

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vu…

Mitigation only
Fix from $1,600 2024-01-09
Application Interface Framework CRITICAL 9.1
CVE-2024-21737

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers…

Mitigation only
Fix from $2,300 2024-01-09
S\/4hana Finance MEDIUM 6.5
CVE-2024-21736

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio…

Mitigation only
Fix from $1,600 2024-01-09
Lt Replication Server HIGH 7.2
CVE-2024-21735

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization …

Mitigation only
Fix from $1,950 2024-01-09
Marketing MEDIUM 5.4
CVE-2024-21734

SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very …

Mitigation only
Fix from $1,600 2024-01-09
Cloud Security Client Go CRITICAL 9.8
CVE-2023-50424

SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions …

Fix: 0.17.0+
Fix from $2,300 2023-12-12
Emarsys Sdk HIGH 7.1
CVE-2023-6542

Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a…

Mitigation only
Fix from $1,950 2023-12-12
Cloud Security Services Integration Library CRITICAL 9.8
CVE-2023-50422

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to…

Fix: 2.17.0 / 3.3.0+
Fix from $2,300 2023-12-12
Sap Xssec CRITICAL 9.8
CVE-2023-50423

SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On…

Fix: 4.1.0+
Fix from $2,300 2023-12-12
Solution Manager MEDIUM 6.4
CVE-2023-49587

SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam…

Mitigation only
Fix from $1,600 2023-12-12
\@sap\/xssec CRITICAL 9.8
CVE-2023-49583

SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. O…

Fix: 3.6.0+
Fix from $2,300 2023-12-12
Netweaver Application Server Abap CRITICAL 9.4
CVE-2023-49581

SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential…

Mitigation only
Fix from $2,300 2023-12-12
Graphical User Interface HIGH 7.3
CVE-2023-49580

SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to …

Mitigation only
Fix from $1,950 2023-12-12
Human Capital Management MEDIUM 6.1
CVE-2023-49577

The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled …

Mitigation only
Fix from $1,600 2023-12-12
Master Data Governance MEDIUM 5.3
CVE-2023-49058

SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus …

Mitigation only
Fix from $1,600 2023-12-12
Commerce Cloud HIGH 8.1
CVE-2023-42481

In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the for…

Mitigation only
Fix from $1,950 2023-12-12
Business Objects Business Intelligence Platform HIGH 7.6
CVE-2023-42478

SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which…

Mitigation only
Fix from $1,950 2023-12-12
Businessobjects Web Intelligence MEDIUM 6.8
CVE-2023-42476

SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents whic…

Mitigation only
Fix from $1,600 2023-12-12
Biller Direct MEDIUM 6.1
CVE-2023-42479

An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scri…

Mitigation only
Fix from $1,600 2023-12-12
Business One HIGH 8.0
CVE-2023-31403

SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any…

Mitigation only
Fix from $1,950 2023-11-14
Netweaver Application Server Abap MEDIUM 5.3
CVE-2023-41366

Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54,…

Mitigation only
Fix from $1,600 2023-11-14
Netweaver Application Server Java MEDIUM 5.3
CVE-2023-42480

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimat…

Mitigation only
Fix from $1,600 2023-11-14
Enable Now Enable Now Consump Del MEDIUM 6.1
CVE-2023-36920

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response heade…

Mitigation only
Fix from $1,600 2023-10-30
Netweaver Application Server Java MEDIUM 6.5
CVE-2023-42477

SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca…

No fix yet
Fix from $1,600 2023-10-10
Powerdesigner HIGH 7.5
CVE-2023-40310

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of ex…

Mitigation only
Fix from $1,950 2023-10-10
S\/4hana MEDIUM 5.4
CVE-2023-42473

S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat…

Mitigation only
Fix from $1,600 2023-10-10
Businessobjects Web Intelligence MEDIUM 5.4
CVE-2023-42474

SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malici…

Mitigation only
Fix from $1,600 2023-10-10
Privileges HIGH 7.8
CVE-2023-40307

An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer ov…

Fix: 1.5.4+
Fix from $1,950 2023-09-28
S4core MEDIUM 5.4
CVE-2023-40625

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated …

Mitigation only
Fix from $1,600 2023-09-12