VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2023-6542HigDec 12, 2023
    risk 0.46cvss 7.1epss 0.00

    Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to…

  • CVE-2023-33993HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and…

  • CVE-2023-30743HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the…

  • CVE-2022-41211HigNov 8, 2022
    risk 0.46cvss 7.0epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which…

  • CVE-2021-27614HigMay 11, 2021
    risk 0.46cvss 7.1epss 0.00

    SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby…

  • CVE-2019-0396HigNov 13, 2019
    risk 0.46cvss 7.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will…

  • CVE-2019-0363HigSep 10, 2019
    risk 0.46cvss 7.1epss 0.01

    Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.

  • CVE-2019-0289HigMay 14, 2019
    risk 0.46cvss 7.1epss 0.01

    Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted.

  • CVE-2019-0283HigApr 10, 2019
    risk 0.46cvss 7.1epss 0.01

    SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests to the server via PI Axis adapter. These requests will be…

  • CVE-2018-2492HigDec 11, 2018
    risk 0.46cvss 7.1epss 0.01

    SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.

  • CVE-2025-42895MedNov 11, 2025
    risk 0.45cvss 6.9epss 0.00

    Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact…

  • CVE-2025-42946MedAug 12, 2025
    risk 0.45cvss 6.9epss 0.01

    Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This…

  • CVE-2025-43001MedJul 8, 2025
    risk 0.45cvss 6.9epss 0.00

    SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by…

  • CVE-2025-42992MedJul 8, 2025
    risk 0.45cvss 6.9epss 0.00

    SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has…

  • CVE-2024-39593MedJul 9, 2024
    risk 0.45cvss 6.9epss 0.00

    SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.

  • CVE-2025-42894MedNov 11, 2025
    risk 0.44cvss 6.8epss 0.00

    Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary…

  • CVE-2025-42892MedNov 11, 2025
    risk 0.44cvss 6.8epss 0.01

    Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of…

  • CVE-2025-42993MedJun 10, 2025
    risk 0.44cvss 6.7epss 0.00

    Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events…

  • CVE-2025-30013MedApr 8, 2025
    risk 0.44cvss 6.7epss 0.01

    SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the…

  • CVE-2025-26654MedApr 8, 2025
    risk 0.44cvss 6.8epss 0.00

    SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on…

  • CVE-2025-26658MedMar 11, 2025
    risk 0.44cvss 6.8epss 0.00

    The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and…

  • CVE-2025-24875MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future…

  • CVE-2025-24874MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP…

  • CVE-2024-47580MedDec 10, 2024
    risk 0.44cvss 6.8epss 0.01

    An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no…

  • CVE-2023-42476MedDec 12, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to…

  • CVE-2023-42474MedOct 10, 2023
    risk 0.44cvss 6.8epss 0.00

    SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.

  • CVE-2023-29187MedApr 11, 2023
    risk 0.44cvss 6.7epss 0.00

    A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various…

  • CVE-2023-26458MedApr 11, 2023
    risk 0.44cvss 6.8epss 0.01

    An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and…

  • CVE-2023-26461MedMar 14, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows…

  • CVE-2023-25615MedMar 14, 2023
    risk 0.44cvss 6.8epss 0.01

    Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database queries over the network and gain access to the unintended…

  • CVE-2022-31594MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.

  • CVE-2021-44235MedDec 14, 2021
    risk 0.44cvss 6.7epss 0.00

    Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction…

  • CVE-2021-33693MedSep 15, 2021
    risk 0.44cvss 6.8epss 0.01

    SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.

  • CVE-2021-27611MedMay 11, 2021
    risk 0.44cvss 6.7epss 0.00

    SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial…

  • CVE-2020-6250MedMay 12, 2020
    risk 0.44cvss 6.8epss 0.01

    SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any…

  • CVE-2020-6245MedMay 12, 2020
    risk 0.44cvss 6.7epss 0.00

    SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

  • CVE-2019-0357MedSep 10, 2019
    risk 0.44cvss 6.7epss 0.00

    The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.

  • CVE-2019-0308MedJun 12, 2019
    risk 0.44cvss 6.8epss 0.01

    An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to…

  • CVE-2026-44754MedJun 9, 2026
    risk 0.43cvss 6.6epss 0.00

    The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its…

  • CVE-2026-0496MedJan 13, 2026
    risk 0.43cvss 6.6epss 0.00

    SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.

  • CVE-2025-42875MedDec 9, 2025
    risk 0.43cvss 6.6epss 0.00

    The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and…

  • CVE-2025-42997MedMay 13, 2025
    risk 0.43cvss 6.6epss 0.00

    Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially…

  • CVE-2025-31332MedApr 8, 2025
    risk 0.43cvss 6.6epss 0.00

    Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability.…

  • CVE-2018-2451MedAug 14, 2018
    risk 0.43cvss 6.6epss 0.01

    XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even…

  • CVE-2018-11415MedMay 24, 2018
    risk 0.43cvss 6.1epss 0.10

    SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

  • CVE-2026-76971MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to…

  • CVE-2026-76968MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure.…

  • CVE-2026-44766MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information,…

  • CVE-2026-66760MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack…

  • CVE-2026-58248MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these…

Page 13 of 40