Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-22125 Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access high… Gui Connector No fix yet Fix from $1,9502024-01-09 MEDIUM 5.4 CVE-2024-21738 SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vu… Netweaver Application Server Abap Mitigation only Fix from $1,6002024-01-09 CRITICAL 9.1 CVE-2024-21737 In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers… Application Interface Framework Mitigation only Fix from $2,3002024-01-09 MEDIUM 6.5 CVE-2024-21736 SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio… S\/4hana Finance Mitigation only Fix from $1,6002024-01-09 HIGH 7.2 CVE-2024-21735 SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization … Lt Replication Server Mitigation only Fix from $1,9502024-01-09 MEDIUM 5.4 CVE-2024-21734 SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very … Marketing Mitigation only Fix from $1,6002024-01-09 CRITICAL 9.8 CVE-2023-50424 SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions … Cloud Security Client Go 0.17.0+ Fix from $2,3002023-12-12 HIGH 7.1 CVE-2023-6542 Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a… Emarsys Sdk Mitigation only Fix from $1,9502023-12-12 CRITICAL 9.8 CVE-2023-50422 SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to… Cloud Security Services Integration Library 2.17.0 / 3.3.0+ Fix from $2,3002023-12-12 CRITICAL 9.8 CVE-2023-50423 SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On… Sap Xssec 4.1.0+ Fix from $2,3002023-12-12 MEDIUM 6.4 CVE-2023-49587 SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of sam… Solution Manager Mitigation only Fix from $1,6002023-12-12 CRITICAL 9.8 CVE-2023-49583 SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. O… \@sap\/xssec 3.6.0+ Fix from $2,3002023-12-12 CRITICAL 9.4 CVE-2023-49581 SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential… Netweaver Application Server Abap Mitigation only Fix from $2,3002023-12-12 HIGH 7.3 CVE-2023-49580 SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to … Graphical User Interface Mitigation only Fix from $1,9502023-12-12 MEDIUM 6.1 CVE-2023-49577 The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled … Human Capital Management Mitigation only Fix from $1,6002023-12-12 MEDIUM 5.3 CVE-2023-49058 SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus … Master Data Governance Mitigation only Fix from $1,6002023-12-12 HIGH 8.1 CVE-2023-42481 In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the for… Commerce Cloud Mitigation only Fix from $1,9502023-12-12 HIGH 7.6 CVE-2023-42478 SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which… Business Objects Business Intelligence Platform Mitigation only Fix from $1,9502023-12-12 MEDIUM 6.8 CVE-2023-42476 SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents whic… Businessobjects Web Intelligence Mitigation only Fix from $1,6002023-12-12 MEDIUM 6.1 CVE-2023-42479 An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scri… Biller Direct Mitigation only Fix from $1,6002023-12-12 HIGH 8.0 CVE-2023-31403 SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any… Business One Mitigation only Fix from $1,9502023-11-14 MEDIUM 5.3 CVE-2023-41366 Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54,… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-11-14 MEDIUM 5.3 CVE-2023-42480 The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimat… Netweaver Application Server Java Mitigation only Fix from $1,6002023-11-14 MEDIUM 6.1 CVE-2023-36920 In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response heade… Enable Now Enable Now Consump Del Mitigation only Fix from $1,6002023-10-30 MEDIUM 6.5 CVE-2023-42477 SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, ca… Netweaver Application Server Java No fix yet Fix from $1,6002023-10-10 HIGH 7.5 CVE-2023-40310 SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of ex… Powerdesigner Mitigation only Fix from $1,9502023-10-10 MEDIUM 5.4 CVE-2023-42473 S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat… S\/4hana Mitigation only Fix from $1,6002023-10-10 MEDIUM 5.4 CVE-2023-42474 SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malici… Businessobjects Web Intelligence Mitigation only Fix from $1,6002023-10-10 HIGH 7.8 CVE-2023-40307 An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer ov… Privileges 1.5.4+ Fix from $1,9502023-09-28 MEDIUM 5.4 CVE-2023-40625 S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated … S4core Mitigation only Fix from $1,6002023-09-12