VYPR

BASIS

by SAP

CVEs (32)

  • CVE-2025-23193MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no…

  • CVE-2025-0053MedJan 14, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the…

  • CVE-2025-42911MedSep 9, 2025
    risk 0.33cvss 5.0epss 0.00

    SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and…

  • CVE-2024-34689MedJul 9, 2024
    risk 0.33cvss 5.0epss 0.00

    WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and…

  • CVE-2024-39599MedJul 9, 2024
    risk 0.31cvss 4.7epss 0.00

    Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidentiality, integrity, and…

  • CVE-2024-22128MedFeb 13, 2024
    risk 0.31cvss 4.7epss 0.00

    SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can…

  • CVE-2023-29109MedApr 11, 2023
    risk 0.29cvss 4.4epss 0.00

    The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip…

  • CVE-2025-42918MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.00

    SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability

  • CVE-2025-42986MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.00

    Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality,…

  • CVE-2020-6307MedJan 14, 2020
    risk 0.28cvss 4.3epss 0.01

    Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.

  • CVE-2024-37180MedJul 9, 2024
    risk 0.27cvss 4.1epss 0.00

    Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low…

  • CVE-2023-29110LowApr 11, 2023
    risk 0.24cvss 3.7epss 0.00

    The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and…

Page 2 of 2