Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-47594 SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser… Netweaver Enterprise Portal Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.4 CVE-2024-45278 SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful … Commerce Backoffice Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.3 CVE-2024-45282 Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property … S\/4 Hana Mitigation only Fix from $1,6002024-10-08 MEDIUM 6.5 CVE-2024-37179 SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting… Businessobjects Business Intelligence Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.8 CVE-2024-45281 SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not d… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002024-09-10 MEDIUM 5.4 CVE-2024-42373 SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of… Student Life Cycle Management Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-39591 SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo… Document Builder Mitigation only Fix from $1,6002024-08-13 HIGH 8.2 CVE-2024-42374 BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve in… Bex Web Java Runtime Export Web Service Mitigation only Fix from $1,9502024-08-13 MEDIUM 6.5 CVE-2024-42376 SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ… Shared Service Framework Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.0 CVE-2024-41737 SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re… Crm Abap Insights Management Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.4 CVE-2024-41735 SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact… Commerce Backoffice Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.8 CVE-2024-41730EPSS 76% In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo… Business Objects Business Intelligence Platform Mitigation only Fix from $2,3002024-08-13 MEDIUM 5.4 CVE-2024-41732 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t… Netweaver Application Server Abap Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-41733 In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear… Commerce Mitigation only Fix from $1,6002024-08-13 CRITICAL 9.1 CVE-2024-33003 Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number… Commerce Cloud Mitigation only Fix from $2,3002024-08-13 MEDIUM 6.3 CVE-2024-33005 Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)… Netweaver Abap Mitigation only Fix from $1,6002024-08-13 MEDIUM 6.1 CVE-2024-39594 SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cro… Business Warehouse Patch available Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-39595 SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-… Business Warehouse Patch available Fix from $1,6002024-07-09 MEDIUM 5.3 CVE-2024-37180 Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with… Sap Basis Patch available Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-37175 SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a… Customer Relationship Management S4fnd Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-37172 SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o… S4core Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2024-37171 SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl… Saptmui Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2024-34689 WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall… Business Workflow Mitigation only Fix from $1,6002024-07-09 HIGH 7.7 CVE-2024-39598 SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin… Customer Relationship Management S4fnd Mitigation only Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2024-39592 Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an … S4core Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2024-37174 Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability… Customer Relationship Management S4fnd Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.7 CVE-2024-39593 SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploi… Landscape Management Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2024-34685 Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the a… Netweaver Knowledge Management And Collaboration \(kmc Cm\) Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2024-37173 Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script… Customer Relationship Management S4fnd Mitigation only Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-37176 SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by ex… Bw\/4hana Patch available Fix from $1,6002024-06-11