Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2022-26106
When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - v…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-26107
When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version …
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-26108
When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-26109
When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - ver…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.1
CVE-2022-26105
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated …
Netweaver Enterprise Portal
Mitigation only
HIGH 7.5
CVE-2022-27658
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering…
Innovation Management
Mitigation only
MEDIUM 5.3
CVE-2022-26103
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to …
Netweaver Application Server Java
Mitigation only
MEDIUM 5.3
CVE-2022-26104
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthor…
Financial Consolidation
Mitigation only
MEDIUM 5.4
CVE-2022-26102
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to acc…
Netweaver Application Server Abap
Mitigation only
CRITICAL 9.8
CVE-2022-26100
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacke…
Sapcar
Mitigation only
MEDIUM 6.1
CVE-2022-26101
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Fiori Launchpad
No fix yet
MEDIUM 6.1
CVE-2022-24399
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipar…
Focused Run
No fix yet
MEDIUM 6.5
CVE-2022-24398
Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat…
Business Objects Business Intelligence Platform
No fix yet
MEDIUM 6.1
CVE-2022-24397
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-…
Netweaver Enterprise Portal
Mitigation only
HIGH 7.8
CVE-2022-24396
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed v…
Simple Diagnostics Agent
after 1.57
MEDIUM 6.1
CVE-2022-24395
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…
Netweaver Enterprise Portal
Mitigation only
HIGH 7.5
CVE-2022-22547
Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a ran…
Simple Diagnostics Agent
1.58+
MEDIUM 5.4
CVE-2022-22546
Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence…
Businessobjects Web Intelligence
Mitigation only
CRITICAL 10.0
CVE-2022-22536 KEVEPSS 98%
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne…
Content Server
Mitigation only
CRITICAL 9.8
CVE-2022-22532
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an u…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.1
CVE-2022-22544
Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents a…
Solution Manager
Mitigation only
HIGH 7.8
CVE-2022-22528
SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, u…
Adaptive Server Enterprise
Mitigation only
HIGH 7.5
CVE-2022-22533
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2022-22540
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute cr…
Netweaver Application Server Abap
Mitigation only
HIGH 7.5
CVE-2022-22543
SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87,…
Netweaver Abap
Mitigation only
MEDIUM 6.5
CVE-2022-22535
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees …
Erp Human Capital Management
Mitigation only
MEDIUM 6.5
CVE-2022-22537
When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versio…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-22538
When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - vers…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-22539
When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 6.5
CVE-2022-22542
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…
S\/4hana
Mitigation only