VYPR

SAP

by SAP

CVEs (10)

  • CVE-2021-44231CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2024-33006CriMay 14, 2024
    risk 0.62cvss 9.6epss 0.01

    An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. 

  • CVE-2026-23689HigFeb 10, 2026
    risk 0.50cvss 7.7epss 0.00

    Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers…

  • CVE-2024-47580MedDec 10, 2024
    risk 0.44cvss 6.8epss 0.01

    An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no…

  • CVE-2025-43009MedMay 13, 2025
    risk 0.41cvss 6.3epss 0.00

    SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.

  • CVE-2025-43008MedMay 13, 2025
    risk 0.38cvss 5.8epss 0.00

    Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

  • CVE-2024-47582MedDec 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

  • CVE-2025-42974MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is no impact on integrity or…

  • CVE-2025-26655LowMar 11, 2025
    risk 0.20cvss 3.1epss 0.00

    SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are…

  • CVE-2006-6010Nov 21, 2006
    risk 0.04cvss epss 0.14

    SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.