Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-34688
Due to unrestricted access to the Meta Model
Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks
on the application, whic…
Netweaver Application Server Java
Patch available
MEDIUM 6.5
CVE-2024-34691
Manage Incoming Payment Files (F1680) of SAP
S/4HANA does not perform necessary authorization checks for an authenticated
user, resulting in escalati…
S\/4 Hana
Patch available
MEDIUM 6.1
CVE-2024-34686
Due to insufficient input validation, SAP CRM
WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script. Wh…
Customer Relationship Management Webclient Ui
Patch available
MEDIUM 5.4
CVE-2024-34690
SAP Student Life Cycle
Management (SLcM) fails to conduct proper authorization checks for
authenticated users, leading to the potential escalation of…
Student Life Cycle Management
Patch available
MEDIUM 6.5
CVE-2024-33001
SAP NetWeaver and ABAP platform allows an
attacker to impede performance for legitimate users by crashing or flooding the
service.
An
impact of th…
Netweaver Application Server Abap
Patch available
MEDIUM 6.5
CVE-2024-34683
An authenticated attacker can upload malicious
file to SAP Document Builder service. When the victim accesses this file, the
attacker is allowed to a…
Document Builder
Patch available
MEDIUM 6.0
CVE-2024-34684
On Unix, SAP BusinessObjects Business
Intelligence Platform (Scheduling) allows an authenticated attacker with
administrator access on the local serv…
Businessobjects Business Intelligence Platform
Patch available
MEDIUM 5.3
CVE-2024-28164
SAP NetWeaver AS Java (CAF - Guided Procedures)
allows an unauthenticated user to access non-sensitive information about the
server which would other…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.0
CVE-2024-34687
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS…
Sap Basis
Patch available
CRITICAL 9.3
CVE-2024-28165
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument UR…
Businessobjects Business Intelligence Platform
Patch available
MEDIUM 6.5
CVE-2024-25646
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system informati…
Businessobjects Web Intelligence
Patch available
MEDIUM 5.3
CVE-2024-27898
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targe…
Netweaver
Mitigation only
MEDIUM 6.1
CVE-2024-27902
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting i…
Netweaver As Abap
Mitigation only
MEDIUM 5.3
CVE-2024-28163
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…
Netweaver Process Integration
Mitigation only
CRITICAL 9.1
CVE-2024-22127
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.5
CVE-2024-22133
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This cou…
Fiori Front End Server
Mitigation only
MEDIUM 5.3
CVE-2024-25644
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2024-25645
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…
Netweaver Enterprise Portal
No fix yet
MEDIUM 5.3
CVE-2024-27900
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…
Abap Platform
Mitigation only
HIGH 7.6
CVE-2024-22129
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user …
Companion
3.1.38+
HIGH 7.5
CVE-2024-24743
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f…
Netweaver Application Server Java
Mitigation only
HIGH 7.4
CVE-2024-25642
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…
Cloud Connector
Mitigation only
HIGH 7.2
CVE-2024-22131
In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…
Abap Platform
Mitigation only
MEDIUM 6.3
CVE-2024-22132
SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behavio…
Ides Ecc
Mitigation only
MEDIUM 6.3
CVE-2024-24739
SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges w…
Bank Account Management
Mitigation only
MEDIUM 5.4
CVE-2024-22130
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEB…
Crm Webclient Ui
Mitigation only
MEDIUM 5.3
CVE-2024-24740
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2024-22126
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters b…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2024-22128
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not suf…
Netweaver Business Client For Html
Mitigation only
HIGH 7.5
CVE-2024-22124
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22,…
Netweaver
Mitigation only