VYPR

Business Planning And Consolidation

by SAP

CVEs (8)

  • CVE-2026-27681CriApr 14, 2026
    risk 0.64cvss 9.9epss 0.01

    Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and…

  • CVE-2023-0016CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

  • CVE-2022-41268HigDec 13, 2022
    risk 0.55cvss 8.5epss 0.01

    In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may…

  • CVE-2017-16349HigAug 2, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue…

  • CVE-2025-42930MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the…

  • CVE-2023-31407MedMay 9, 2023
    risk 0.35cvss 5.4epss 0.00

    SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the…

  • CVE-2023-23851MedFeb 14, 2023
    risk 0.35cvss 5.4epss 0.00

    SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions…

  • CVE-2020-6368MedOct 15, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate…