VYPR

SAP Oil & Gas

by SAP

CVEs (2)

  • CVE-2024-44112MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect…

  • CVE-2014-4006Jun 9, 2014
    risk 0.00cvss epss 0.01

    The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.