Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Solution Manager HIGH 7.2
CVE-2023-36925

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitat…

Mitigation only
Fix from $1,950 2023-07-11
Enable Now MEDIUM 6.1
CVE-2023-36918

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options respons…

Mitigation only
Fix from $1,600 2023-07-11
Enable Now MEDIUM 5.3
CVE-2023-36919

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response heade…

Mitigation only
Fix from $1,600 2023-07-11
Web Dispatcher CRITICAL 9.4
CVE-2023-33987

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBD…

Mitigation only
Fix from $2,300 2023-07-11
Web Dispatcher CRITICAL 9.4
CVE-2023-35871

The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KER…

Mitigation only
Fix from $2,300 2023-07-11
Netweaver Bi Content HIGH 8.1
CVE-2023-33989

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal…

Mitigation only
Fix from $1,950 2023-07-11
S4core HIGH 7.3
CVE-2023-35870

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce…

Mitigation only
Fix from $1,950 2023-07-11
Sql Anywhere HIGH 7.1
CVE-2023-33990

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with …

Mitigation only
Fix from $1,950 2023-07-11
Business Warehouse MEDIUM 6.5
CVE-2023-33992

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, …

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35872

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain funct…

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35873

The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functi…

Mitigation only
Fix from $1,600 2023-07-11
Enable Now MEDIUM 6.1
CVE-2023-33988

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-…

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Application Server For Java MEDIUM 5.3
CVE-2023-31405

SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the …

Mitigation only
Fix from $1,600 2023-07-11
Ui HIGH 8.2
CVE-2023-33991

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-contr…

Mitigation only
Fix from $1,950 2023-06-13
Master Data Synchronization MEDIUM 6.1
CVE-2023-32115

An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additio…

Mitigation only
Fix from $1,600 2023-06-13
Netweaver MEDIUM 6.1
CVE-2023-33985

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Si…

Mitigation only
Fix from $1,600 2023-06-13
Customer Relationship Management Abap MEDIUM 6.1
CVE-2023-33986

SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Si…

Mitigation only
Fix from $1,600 2023-06-13
Digital Manufacturing MEDIUM 5.7
CVE-2023-2827

SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of…

Mitigation only
Fix from $1,600 2023-06-13
Netweaver MEDIUM 5.4
CVE-2023-33984

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized …

Mitigation only
Fix from $1,600 2023-06-13
Gui For Windows CRITICAL 9.3
CVE-2023-32113

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clic…

Fix: 7.70+
Fix from $2,300 2023-05-09
Netweaver Application Server For Java CRITICAL 9.1
CVE-2023-30744

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and…

Mitigation only
Fix from $2,300 2023-05-09
Businessobjects Business Intelligence HIGH 7.6
CVE-2023-30740

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is oth…

Mitigation only
Fix from $1,950 2023-05-09
Powerdesigner Proxy HIGH 7.5
CVE-2023-32111

In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy serve…

Mitigation only
Fix from $1,950 2023-05-09
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2023-30741

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to r…

Mitigation only
Fix from $1,600 2023-05-09
Customer Relationship Management S4fnd MEDIUM 6.1
CVE-2023-30742

SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 74…

Mitigation only
Fix from $1,600 2023-05-09
Sapui5 MEDIUM 6.1
CVE-2023-30743

Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedT…

Mitigation only
Fix from $1,600 2023-05-09
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2023-31406

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to r…

Mitigation only
Fix from $1,600 2023-05-09
S4core MEDIUM 5.5
CVE-2023-32112

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SA…

Mitigation only
Fix from $1,600 2023-05-09
Business Planning And Consolidation MEDIUM 5.4
CVE-2023-31407

SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Script…

Mitigation only
Fix from $1,600 2023-05-09
Businessobjects Business Intelligence MEDIUM 5.0
CVE-2023-31404

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to …

Mitigation only
Fix from $1,600 2023-05-09