Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Businessobjects Business Intelligence HIGH 7.2
CVE-2023-28762

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the log…

Mitigation only
Fix from $1,950 2023-05-09
Businessobjects MEDIUM 5.9
CVE-2023-28764

SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the netwo…

Mitigation only
Fix from $1,600 2023-05-09
Customer Relationship Management Webclient Ui MEDIUM 5.4
CVE-2023-29188

SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746…

Mitigation only
Fix from $1,600 2023-05-09
Customer Relationship Management S4fnd MEDIUM 5.4
CVE-2023-29189

SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated a…

Mitigation only
Fix from $1,600 2023-04-11
Sapsetup MEDIUM 6.7
CVE-2023-29187

A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting …

Mitigation only
Fix from $1,600 2023-04-11
Netweaver As Abap Business Server Pages MEDIUM 6.5
CVE-2023-29185

SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker auth…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver MEDIUM 6.5
CVE-2023-29186EPSS 23%

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrit…

Mitigation only
Fix from $1,600 2023-04-11
Application Interface MEDIUM 5.4
CVE-2023-29112

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS clas…

Mitigation only
Fix from $1,600 2023-04-11
Abap Platform MEDIUM 5.4
CVE-2023-29110

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, applicati…

Mitigation only
Fix from $1,600 2023-04-11
Diagnostics Agent CRITICAL 9.8
CVE-2023-27497

Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker …

Mitigation only
Fix from $2,300 2023-04-11
Businessobjects Business Intelligence CRITICAL 9.8
CVE-2023-28765EPSS 15%

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to…

Mitigation only
Fix from $2,300 2023-04-11
Landscape Management HIGH 8.7
CVE-2023-26458

An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscap…

Mitigation only
Fix from $1,950 2023-04-11
Diagnostics Agent HIGH 8.1
CVE-2023-27267EPSS 14%

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with…

Mitigation only
Fix from $1,950 2023-04-11
Netweaver Enterprise Portal MEDIUM 6.5
CVE-2023-28761

In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access …

Mitigation only
Fix from $1,600 2023-04-11
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-28763

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-ad…

Mitigation only
Fix from $1,600 2023-04-11
Customer Relationship Management MEDIUM 6.3
CVE-2023-27897

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver MEDIUM 6.1
CVE-2023-27499

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficien…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver As Java For Deploy Service MEDIUM 5.3
CVE-2023-24527

SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity ena…

Mitigation only
Fix from $1,600 2023-04-11
Abap Platform Kernel MEDIUM 5.3
CVE-2023-29108

The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netma…

Mitigation only
Fix from $1,600 2023-04-11
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27501

SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to ex…

Mitigation only
Fix from $2,300 2023-03-14
Solution Manager HIGH 8.8
CVE-2023-27893

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP manag…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap HIGH 8.1
CVE-2023-27500

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this att…

Mitigation only
Fix from $1,950 2023-03-14
Businessobjects Business Intelligence HIGH 7.5
CVE-2023-27896

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application ser…

Mitigation only
Fix from $1,950 2023-03-14
Authenticator MEDIUM 6.5
CVE-2023-27895

SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile dev…

Mitigation only
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2023-27894

SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameter…

Mitigation only
Fix from $1,600 2023-03-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2023-27271

In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the…

Mitigation only
Fix from $1,950 2023-03-14
Host Agent HIGH 7.2
CVE-2023-27498

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service t…

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap CRITICAL 9.6
CVE-2023-27269

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows a…

Mitigation only
Fix from $2,300 2023-03-14
Netweaver Application Server Abap HIGH 7.4
CVE-2023-26459

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, …

Mitigation only
Fix from $1,950 2023-03-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-27270

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has mult…

Mitigation only
Fix from $1,600 2023-03-14