VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2024-33005MedAug 13, 2024
    risk 0.41cvss 6.3epss 0.00

    Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on…

  • CVE-2024-24739MedFeb 13, 2024
    risk 0.41cvss 6.3epss 0.00

    SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact on confidentiality, integrity and availability of the application.

  • CVE-2023-40307MedSep 28, 2023
    risk 0.41cvss 6.3epss 0.00

    An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of…

  • CVE-2023-40621MedSep 12, 2023
    risk 0.41cvss 6.3epss 0.03

    SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt…

  • CVE-2023-35870MedJul 11, 2023
    risk 0.41cvss 6.3epss 0.00

    When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a…

  • CVE-2023-30740MedMay 9, 2023
    risk 0.41cvss 6.3epss 0.00

    SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality, limited impact on integrity and…

  • CVE-2021-42063MedDec 14, 2021
    risk 0.41cvss 6.1epss 0.22

    A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.

  • CVE-2021-21473MedJun 9, 2021
    risk 0.41cvss 6.3epss 0.01

    SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute…

  • CVE-2020-6290MedJul 14, 2020
    risk 0.41cvss 6.3epss 0.01

    SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.

  • CVE-2019-0386MedNov 13, 2019
    risk 0.41cvss 6.3epss 0.01

    Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an…

  • CVE-2018-2409MedApr 10, 2018
    risk 0.41cvss 6.3epss 0.01

    Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.

  • CVE-2016-5847MedAug 13, 2016
    risk 0.41cvss 5.8epss 0.01

    SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.

  • CVE-2026-66771MedAug 11, 2026
    risk 0.40cvss 6.1epss 0.00

    SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation…

  • CVE-2026-44746MedJun 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation,…

  • CVE-2026-40137MedMay 12, 2026
    risk 0.40cvss 6.1epss 0.00

    SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This…

  • CVE-2026-34257MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and…

  • CVE-2026-27674MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the…

  • CVE-2026-0512MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL, that if accessed by a victim, results in execution of malicious content within the victim's…

  • CVE-2026-0489MedMar 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS)…

  • CVE-2026-24328MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in…

  • CVE-2026-24323MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact…

  • CVE-2026-0505MedFeb 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no…

  • CVE-2026-0514MedJan 13, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow…

  • CVE-2026-0499MedJan 13, 2026
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information,…

  • CVE-2025-42872MedDec 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive…

  • CVE-2025-42924MedNov 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on…

  • CVE-2025-42893MedNov 11, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the…

  • CVE-2025-42886MedNov 11, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page…

  • CVE-2025-42938MedSep 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s…

  • CVE-2025-42920MedSep 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim clicks on the link, the injected input is processed during the…

  • CVE-2025-42975MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing…

  • CVE-2025-42948MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s…

  • CVE-2025-42945MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited…

  • CVE-2025-42942MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the…

  • CVE-2025-42956MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page…

  • CVE-2025-42985MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact…

  • CVE-2025-42981MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's…

  • CVE-2025-42969MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On…

  • CVE-2025-42962MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and…

  • CVE-2025-43006MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute malicious scripts in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the…

  • CVE-2025-31329MedMay 13, 2025
    risk 0.40cvss 6.2epss 0.00

    SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive…

  • CVE-2025-30010MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a…

  • CVE-2025-30009MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on…

  • CVE-2025-26659MedMar 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful…

  • CVE-2025-25242MedMar 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its…

  • CVE-2025-24867MedFeb 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a…

  • CVE-2024-45279MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be…

  • CVE-2024-42378MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it…

  • CVE-2024-39594MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and…

  • CVE-2024-37174MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

Page 17 of 40