Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-0024 SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecti… Solution Manager Mitigation only Fix from $1,6002023-02-14 HIGH 8.8 CVE-2023-0022 SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-01-10 MEDIUM 5.7 CVE-2023-0023 In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directl… Bank Account Management Mitigation only Fix from $1,6002023-01-10 CRITICAL 9.8 CVE-2023-0014 SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERN… Netweaver Application Server Abap Mitigation only Fix from $2,3002023-01-10 CRITICAL 9.8 CVE-2023-0017EPSS 16% An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use… Netweaver Application Server For Java Mitigation only Fix from $2,3002023-01-10 HIGH 8.8 CVE-2023-0016 SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL … Business Planning And Consolidation Mitigation only Fix from $1,9502023-01-10 MEDIUM 6.1 CVE-2023-0018 Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002023-01-10 MEDIUM 5.4 CVE-2023-0015 In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type… Business Objects Business Intelligence Platform Mitigation only Fix from $1,6002023-01-10 MEDIUM 6.7 CVE-2023-0012 In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with… Host Agent Mitigation only Fix from $1,6002023-01-10 MEDIUM 6.1 CVE-2023-0013 The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABA… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-01-10 MEDIUM 6.5 CVE-2022-41274 SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive d… Disclosure Management Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.1 CVE-2022-41273 Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicio… Contract Lifecycle Manager Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.1 CVE-2022-41275 In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in … Solution Manager Mitigation only Fix from $1,6002022-12-13 HIGH 8.6 CVE-2022-41272 An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver P… Netweaver Process Integration Mitigation only Fix from $1,9502022-12-13 CRITICAL 9.4 CVE-2022-41271 An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - vers… Netweaver Process Integration Mitigation only Fix from $2,3002022-12-13 HIGH 8.8 CVE-2022-41264 Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow… Basis Mitigation only Fix from $1,9502022-12-13 HIGH 8.8 CVE-2022-41267 SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec… Business Objects Business Intelligence Platform Mitigation only Fix from $1,9502022-12-13 HIGH 7.5 CVE-2022-41268 In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CP… Business Planning And Consolidation No fix yet Fix from $1,9502022-12-13 MEDIUM 6.1 CVE-2022-41266 Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs … Commerce Webservices 2.0 Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.1 CVE-2022-41262 Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a sc… Netweaver Application Server Java Mitigation only Fix from $1,6002022-12-12 MEDIUM 5.5 CVE-2022-41261 SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data… Solution Manager Mitigation only Fix from $1,6002022-12-12 MEDIUM 6.0 CVE-2022-31596 Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Busi… Business Objects Business Intelligence Platform Mitigation only Fix from $1,6002022-12-12 MEDIUM 6.1 CVE-2022-41260 SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject … Financial Consolidation Mitigation only Fix from $1,6002022-11-08 HIGH 8.7 CVE-2022-41214 Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a … Netweaver Application Server Abap Mitigation only Fix from $1,9502022-11-08 MEDIUM 6.5 CVE-2022-41258 Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when ru… Financial Consolidation Mitigation only Fix from $1,6002022-11-08 MEDIUM 6.5 CVE-2022-41259 SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashi… Sql Anywhere Mitigation only Fix from $1,6002022-11-08 HIGH 7.8 CVE-2022-41211 Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and … 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.4 CVE-2022-41208 Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter curr… Financial Consolidation Mitigation only Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-41203 In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can … Businessobjects Business Intelligence Mitigation only Fix from $1,9502022-11-08 MEDIUM 6.1 CVE-2022-41205 SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr… Gui Mitigation only Fix from $1,6002022-11-08