Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2023-40623 SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and lin… Businessobjects Mitigation only Fix from $1,9502023-09-12 MEDIUM 5.4 CVE-2023-40624 SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702,… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-09-12 CRITICAL 9.9 CVE-2023-40622 SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attack… Businessobjects Business Intelligence Mitigation only Fix from $2,3002023-09-12 CRITICAL 9.8 CVE-2023-40309 SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated … Commoncryptolib Mitigation only Fix from $2,3002023-09-12 MEDIUM 6.3 CVE-2023-40621 SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecti… Powerdesigner Mitigation only Fix from $1,6002023-09-12 HIGH 7.3 CVE-2023-42472 Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-09-12 HIGH 7.5 CVE-2023-40308 SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a… Commoncryptolib Mitigation only Fix from $1,9502023-09-12 MEDIUM 5.3 CVE-2023-37489 Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticat… Businessobjects Business Intelligence Mitigation only Fix from $1,6002023-09-12 MEDIUM 5.3 CVE-2023-41367 Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain acce… Netweaver Mitigation only Fix from $1,6002023-09-12 MEDIUM 5.3 CVE-2023-41368 The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by … S\/4 Hana Mitigation only Fix from $1,6002023-09-12 MEDIUM 6.1 CVE-2023-40306 SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR… S\/4hana Mitigation only Fix from $1,6002023-09-08 HIGH 8.1 CVE-2023-39438 A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing spec… Contributor License Agreement Assistant 2.13.1+ Fix from $1,9502023-08-15 CRITICAL 9.8 CVE-2023-39439 SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphra… Commerce Cloud Mitigation only Fix from $2,3002023-08-08 MEDIUM 5.8 CVE-2023-39436 SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relati… Supplier Relationship Management Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.4 CVE-2023-39437 SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it deliver… Business One Mitigation only Fix from $1,6002023-08-08 CRITICAL 9.0 CVE-2023-37490 SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a … Businessobjects Business Intelligence Mitigation only Fix from $2,3002023-08-08 HIGH 8.8 CVE-2023-37491 The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL… Message Server Mitigation only Fix from $1,9502023-08-08 MEDIUM 6.5 CVE-2023-37492 SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BAS… Netweaver Application Server Abap Mitigation only Fix from $1,6002023-08-08 MEDIUM 6.1 CVE-2023-37488 In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, … Netweaver Process Integration Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.3 CVE-2023-37487 SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended … Business One Mitigation only Fix from $1,6002023-08-08 CRITICAL 9.8 CVE-2023-37483 SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back… Powerdesigner Mitigation only Fix from $2,3002023-08-08 HIGH 7.5 CVE-2023-37486 Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access informatio… Commerce Cloud Mitigation only Fix from $1,9502023-08-08 MEDIUM 5.3 CVE-2023-36926 Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c… Host Agent Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.3 CVE-2023-37484 SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt… Powerdesigner Mitigation only Fix from $1,6002023-08-08 HIGH 7.8 CVE-2023-36923 SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious… Powerdesigner Mitigation only Fix from $1,9502023-08-08 HIGH 7.5 CVE-2023-33993 B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network … Business One Mitigation only Fix from $1,9502023-08-08 HIGH 8.8 CVE-2023-36922 Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arb… Netweaver Mitigation only Fix from $1,9502023-07-11 HIGH 7.5 CVE-2023-36917 SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to… Businessobjects Business Intelligence Mitigation only Fix from $1,9502023-07-11 HIGH 7.4 CVE-2023-35874 SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53,… Netweaver Application Server Abap Mitigation only Fix from $1,9502023-07-11 HIGH 7.2 CVE-2023-36921 SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics… Solution Manager Mitigation only Fix from $1,9502023-07-11