Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2022-22534
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user …
Netweaver
Mitigation only
HIGH 8.1
CVE-2022-22530
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…
S\/4hana
Mitigation only
HIGH 8.1
CVE-2022-22531
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…
S\/4hana
Mitigation only
MEDIUM 6.1
CVE-2022-22529
SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker p…
Enterprise Threat Detection
Mitigation only
MEDIUM 5.5
CVE-2021-44234
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos…
Business One
Mitigation only
CRITICAL 9.8
CVE-2021-42064
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce -…
Commerce
Mitigation only
CRITICAL 9.8
CVE-2021-44231
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…
Abap Platform
Mitigation only
HIGH 8.8
CVE-2021-44233
SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c…
Access Control
Mitigation only
HIGH 7.7
CVE-2021-44232
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to ful…
Saf T Framework
Mitigation only
MEDIUM 6.7
CVE-2021-44235
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow a…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2021-42063EPSS 22%
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component with…
Knowledge Warehouse
No fix yet
MEDIUM 5.4
CVE-2021-42061
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting i…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 8.8
CVE-2021-40502
SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es…
Commerce
Mitigation only
HIGH 8.1
CVE-2021-40501
SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resul…
Abap Platform Kernel
Mitigation only
HIGH 7.8
CVE-2021-40503
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient priv…
Gui For Windows
7.60+
MEDIUM 5.9
CVE-2021-41251
@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a…
Cloud Sdk
1.52.0+
CRITICAL 9.8
CVE-2021-40499
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…
Netweaver Application Server Abap
Mitigation only
HIGH 7.5
CVE-2021-40500
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.5
CVE-2021-40498
A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prev…
Successfactors Mobile
2108+
MEDIUM 5.3
CVE-2021-40495
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 75…
Netweaver Abap
Mitigation only
MEDIUM 5.3
CVE-2021-40497
SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive da…
Businessobjects Analysis
Mitigation only
CRITICAL 9.8
CVE-2021-38180
SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during…
Business One
Mitigation only
HIGH 8.8
CVE-2021-38178
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, …
Netweaver Abap
Mitigation only
HIGH 7.5
CVE-2021-38181
SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent leg…
Netweaver Abap
Mitigation only
MEDIUM 6.1
CVE-2021-38183
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to…
Netweaver
Mitigation only
CRITICAL 9.9
CVE-2021-33690EPSS 68%
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions -…
Netweaver Development Infrastructure
Patch available
CRITICAL 9.1
CVE-2021-33695
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
Cloud Connector
Patch available
CRITICAL 9.1
CVE-2021-33701
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 202…
Dmis
No fix yet
HIGH 8.8
CVE-2021-33698
SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file…
Business One
Patch available
HIGH 8.8
CVE-2021-33704
The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricte…
Business One
Patch available