Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2024-47594
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser…
Netweaver Enterprise Portal
Mitigation only
MEDIUM 5.4
CVE-2024-45278
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful …
Commerce Backoffice
Mitigation only
MEDIUM 5.3
CVE-2024-45282
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property …
S\/4 Hana
Mitigation only
MEDIUM 6.5
CVE-2024-37179
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.8
CVE-2024-45281
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not d…
Businessobjects Business Intelligence Platform
Patch available
MEDIUM 5.4
CVE-2024-42373
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…
Student Life Cycle Management
Mitigation only
MEDIUM 5.3
CVE-2024-39591
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo…
Document Builder
Mitigation only
HIGH 8.2
CVE-2024-42374
BEx Web Java Runtime Export Web Service does not
sufficiently validate an XML document accepted from an untrusted source. An
attacker can retrieve in…
Bex Web Java Runtime Export Web Service
Mitigation only
MEDIUM 6.5
CVE-2024-42376
SAP Shared Service Framework does not perform necessary
authorization check for an authenticated user, resulting in escalation of
privileges. On succ…
Shared Service Framework
Mitigation only
MEDIUM 5.0
CVE-2024-41737
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints in the
internal network by specially crafting HTTP re…
Crm Abap Insights Management
Mitigation only
MEDIUM 5.4
CVE-2024-41735
SAP Commerce Backoffice does not sufficiently
encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)
vulnerability causing low impact…
Commerce Backoffice
Mitigation only
CRITICAL 9.8
CVE-2024-41730EPSS 76%
In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a lo…
Business Objects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2024-41732
SAP NetWeaver Application Server ABAP allows
an unauthenticated attacker to craft a URL link that could bypass allowlist
controls. Depending on t…
Netweaver Application Server Abap
Mitigation only
MEDIUM 5.3
CVE-2024-41733
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to lear…
Commerce
Mitigation only
CRITICAL 9.1
CVE-2024-33003
Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile number…
Commerce Cloud
Mitigation only
MEDIUM 6.3
CVE-2024-33005
Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java)…
Netweaver Abap
Mitigation only
MEDIUM 6.1
CVE-2024-39594
SAP Business Warehouse - Business Planning and
Simulation application does not sufficiently encode user controlled inputs,
resulting in Reflected Cro…
Business Warehouse
Patch available
MEDIUM 5.4
CVE-2024-39595
SAP Business Warehouse - Business Planning and
Simulation application does not sufficiently encode user-controlled inputs,
resulting in Stored Cross-…
Business Warehouse
Patch available
MEDIUM 5.3
CVE-2024-37180
Under certain conditions SAP NetWeaver
Application Server for ABAP and ABAP Platform allows an attacker to access
remote-enabled function module with…
Sap Basis
Patch available
MEDIUM 6.5
CVE-2024-37175
SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow a…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.4
CVE-2024-37172
SAP S/4HANA Finance (Advanced Payment
Management) does not perform necessary authorization check for an authenticated
user, resulting in escalation o…
S4core
Mitigation only
MEDIUM 5.0
CVE-2024-37171
SAP Transportation Management (Collaboration
Portal) allows an attacker with non-administrative privileges to send a crafted
request from a vulnerabl…
Saptmui
Mitigation only
MEDIUM 5.0
CVE-2024-34689
WebFlow Services of SAP Business Workflow allows
an authenticated attacker to enumerate accessible HTTP endpoints in the
internal network by speciall…
Business Workflow
Mitigation only
HIGH 7.7
CVE-2024-39598
SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP endpoints in the internal
network by specially craftin…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 6.5
CVE-2024-39592
Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.
This
allows an …
S4core
Mitigation only
MEDIUM 6.1
CVE-2024-37174
Custom CSS support option in SAP CRM WebClient
UI does not sufficiently encode user-controlled inputs resulting in Cross-Site
Scripting vulnerability…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.7
CVE-2024-39593
SAP Landscape Management allows an authenticated
user to read confidential data disclosed by the REST Provider Definition
response. Successful exploi…
Landscape Management
Mitigation only
MEDIUM 6.1
CVE-2024-34685
Due to weak encoding of user-controlled input in
SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can
be executed in the a…
Netweaver Knowledge Management And Collaboration \(kmc Cm\)
Mitigation only
MEDIUM 6.1
CVE-2024-37173
Due to insufficient input validation, SAP
CRM WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script…
Customer Relationship Management S4fnd
Mitigation only
MEDIUM 5.4
CVE-2024-37176
SAP BW/4HANA Transformation and Data Transfer
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by ex…
Bw\/4hana
Patch available