VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2024-37173MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to…

  • CVE-2024-34685MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the…

  • CVE-2024-34686MedJun 11, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access…

  • CVE-2024-33002MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.

  • CVE-2024-32733MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker…

  • CVE-2024-22126MedFeb 13, 2024
    risk 0.40cvss 6.1epss 0.01

    The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on…

  • CVE-2023-49577MedDec 12, 2023
    risk 0.40cvss 6.1epss 0.00

    The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact…

  • CVE-2023-42479MedDec 12, 2023
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system. This can result in the disclosure or modification of non-sensitive information.

  • CVE-2023-36920MedOct 30, 2023
    risk 0.40cvss 6.1epss 0.00

    In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or…

  • CVE-2023-40623MedSep 12, 2023
    risk 0.40cvss 6.2epss 0.00

    SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system…

  • CVE-2023-40306MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.

  • CVE-2023-37488MedAug 8, 2023
    risk 0.40cvss 6.1epss 0.00

    In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on…

  • CVE-2023-36918MedJul 11, 2023
    risk 0.40cvss 6.1epss 0.00

    In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site…

  • CVE-2023-33988MedJul 11, 2023
    risk 0.40cvss 6.1epss 0.00

    In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-XSS-Protection response headers are not implemented, allowing an unauthenticated attacker to attempt reflected cross-site…

  • CVE-2023-33986MedJun 13, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and…

  • CVE-2023-33985MedJun 13, 2023
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or…

  • CVE-2023-31406MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2023-30742MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored…

  • CVE-2023-30741MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information…

  • CVE-2023-27499MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a…

  • CVE-2023-27895MedMar 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanumeric token during the token setup. On…

  • CVE-2023-26457MedMar 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive information but cannot delete the data.

  • CVE-2023-0021MedMar 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are…

  • CVE-2023-25614MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain…

  • CVE-2023-24529MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site…

  • CVE-2023-24522MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended…

  • CVE-2023-24521MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and…

  • CVE-2023-23860MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or…

  • CVE-2023-23859MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.

  • CVE-2023-23858MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and…

  • CVE-2023-23853MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious…

  • CVE-2023-23852MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2023-0013MedJan 10, 2023
    risk 0.40cvss 6.1epss 0.00

    The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On…

  • CVE-2022-41275MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.00

    In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing…

  • CVE-2022-41262MedDec 12, 2022
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on…

  • CVE-2022-41260MedNov 8, 2022
    risk 0.40cvss 6.1epss 0.00

    SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on…

  • CVE-2022-41207MedNov 8, 2022
    risk 0.40cvss 6.1epss 0.00

    SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or…

  • CVE-2022-39800MedOct 11, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information…

  • CVE-2022-35226MedOct 11, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack,…

  • CVE-2022-39799MedSep 13, 2022
    risk 0.40cvss 6.1epss 0.01

    An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

  • CVE-2022-35298MedSep 13, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could…

  • CVE-2022-35227MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script…

  • CVE-2022-35225MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to…

  • CVE-2022-35224MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of…

  • CVE-2022-35172MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-35170MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to…

  • CVE-2022-32247MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker…

  • CVE-2022-29618MedJun 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an…

  • CVE-2022-27656MedMay 11, 2022
    risk 0.40cvss 6.1epss 0.01

    The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-28770MedApr 12, 2022
    risk 0.40cvss 6.1epss 0.01

    Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on…

Page 18 of 40