SAP
by SAP
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44231 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2021 | Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | ||
| CVE-2024-33006 | Cri | 0.62 | 9.6 | 0.01 | May 14, 2024 | An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. | ||
| CVE-2026-23689 | Hig | 0.50 | 7.7 | 0.00 | Feb 10, 2026 | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers… | ||
| CVE-2024-47580 | Med | 0.44 | 6.8 | 0.01 | Dec 10, 2024 | An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no… | ||
| CVE-2025-43009 | Med | 0.41 | 6.3 | 0.00 | May 13, 2025 | SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application. | ||
| CVE-2025-43008 | Med | 0.38 | 5.8 | 0.00 | May 13, 2025 | Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability. | ||
| CVE-2024-47582 | Med | 0.34 | 5.3 | 0.00 | Dec 10, 2024 | Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application. | ||
| CVE-2025-42974 | Med | 0.28 | 4.3 | 0.00 | Jul 8, 2025 | Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is no impact on integrity or… | ||
| CVE-2025-26655 | Low | 0.20 | 3.1 | 0.00 | Mar 11, 2025 | SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are… | ||
| CVE-2006-6010 | 0.04 | — | 0.14 | Nov 21, 2006 | SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747. |
- risk 0.64cvss 9.8epss 0.01
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- risk 0.62cvss 9.6epss 0.01
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
- risk 0.50cvss 7.7epss 0.00
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers…
- risk 0.44cvss 6.8epss 0.01
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no…
- risk 0.41cvss 6.3epss 0.00
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.
- risk 0.38cvss 5.8epss 0.00
Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.
- risk 0.34cvss 5.3epss 0.00
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
- risk 0.28cvss 4.3epss 0.00
Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is no impact on integrity or…
- risk 0.20cvss 3.1epss 0.00
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are…
- CVE-2006-6010Nov 21, 2006risk 0.04cvss —epss 0.14
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747.