Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-22534 Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user … Netweaver Mitigation only Fix from $1,6002022-02-09 HIGH 8.1 CVE-2022-22530 The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.… S\/4hana Mitigation only Fix from $1,9502022-01-14 HIGH 8.1 CVE-2022-22531 The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.… S\/4hana Mitigation only Fix from $1,9502022-01-14 MEDIUM 6.1 CVE-2022-22529 SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker p… Enterprise Threat Detection Mitigation only Fix from $1,6002022-01-14 MEDIUM 5.5 CVE-2021-44234 SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos… Business One Mitigation only Fix from $1,6002022-01-14 CRITICAL 9.8 CVE-2021-42064 If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce -… Commerce Mitigation only Fix from $2,3002021-12-14 CRITICAL 9.8 CVE-2021-44231 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t… Abap Platform Mitigation only Fix from $2,3002021-12-14 HIGH 8.8 CVE-2021-44233 SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c… Access Control Mitigation only Fix from $1,9502021-12-14 HIGH 7.7 CVE-2021-44232 SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to ful… Saf T Framework Mitigation only Fix from $1,9502021-12-14 MEDIUM 6.7 CVE-2021-44235 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow a… Netweaver Application Server Abap Mitigation only Fix from $1,6002021-12-14 MEDIUM 6.1 CVE-2021-42063EPSS 22% A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component with… Knowledge Warehouse No fix yet Fix from $1,6002021-12-14 MEDIUM 5.4 CVE-2021-42061 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting i… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002021-12-14 HIGH 8.8 CVE-2021-40502 SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es… Commerce Mitigation only Fix from $1,9502021-11-10 HIGH 8.1 CVE-2021-40501 SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul… Abap Platform Kernel Mitigation only Fix from $1,9502021-11-10 HIGH 7.8 CVE-2021-40503 An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient priv… Gui For Windows 7.60+ Fix from $1,9502021-11-10 MEDIUM 5.9 CVE-2021-41251 @sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a… Cloud Sdk 1.52.0+ Fix from $1,6002021-11-05 CRITICAL 9.8 CVE-2021-40499 Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,… Netweaver Application Server Abap Mitigation only Fix from $2,3002021-10-12 HIGH 7.5 CVE-2021-40500 SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502021-10-12 MEDIUM 5.5 CVE-2021-40498 A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prev… Successfactors Mobile 2108+ Fix from $1,6002021-10-12 MEDIUM 5.3 CVE-2021-40495 There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 75… Netweaver Abap Mitigation only Fix from $1,6002021-10-12 MEDIUM 5.3 CVE-2021-40497 SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive da… Businessobjects Analysis Mitigation only Fix from $1,6002021-10-12 CRITICAL 9.8 CVE-2021-38180 SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during… Business One Mitigation only Fix from $2,3002021-10-12 HIGH 8.8 CVE-2021-38178 The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, … Netweaver Abap Mitigation only Fix from $1,9502021-10-12 HIGH 7.5 CVE-2021-38181 SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent leg… Netweaver Abap Mitigation only Fix from $1,9502021-10-12 MEDIUM 6.1 CVE-2021-38183 SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to… Netweaver Mitigation only Fix from $1,6002021-10-12 CRITICAL 9.9 CVE-2021-33690EPSS 68% Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -… Netweaver Development Infrastructure Patch available Fix from $2,3002021-09-15 CRITICAL 9.1 CVE-2021-33695 Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate. Cloud Connector Patch available Fix from $2,3002021-09-15 CRITICAL 9.1 CVE-2021-33701 DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 202… Dmis No fix yet Fix from $2,3002021-09-15 HIGH 8.8 CVE-2021-33698 SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file… Business One Patch available Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-33704 The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte… Business One Patch available Fix from $1,9502021-09-15