VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2022-28216MedApr 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access…

  • CVE-2022-26105MedApr 12, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker…

  • CVE-2022-26101MedMar 10, 2022
    risk 0.40cvss 6.1epss 0.01

    Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-24399MedMar 10, 2022
    risk 0.40cvss 6.1epss 0.01

    The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-24397MedMar 10, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify…

  • CVE-2022-24395MedMar 10, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2022-22534MedFeb 9, 2022
    risk 0.40cvss 6.1epss 0.01

    Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact…

  • CVE-2022-22529MedJan 14, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 standard controls, the UI5 framework provides automated output…

  • CVE-2021-38183MedOct 12, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web…

  • CVE-2021-33697MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2021-33691MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a…

  • CVE-2021-33675MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing and to execute arbitrary code on the victim's browser.

  • CVE-2021-33674MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new email and to execute arbitrary code on the victim's…

  • CVE-2021-33673MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the employee directory and to…

  • CVE-2021-33707MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

  • CVE-2021-33703MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack results in Reflected Cross-Site Scripting (XSS)…

  • CVE-2021-33702MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a successful attack, a victim opens the report, and the…

  • CVE-2018-17865MedAug 9, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2018-17862MedAug 9, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2018-17861MedAug 9, 2021
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-33666MedJun 9, 2021
    risk 0.40cvss 6.1epss 0.01

    When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.

  • CVE-2021-21490MedJun 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data…

  • CVE-2021-27612MedMay 11, 2021
    risk 0.40cvss 6.1epss 0.01

    In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.

  • CVE-2021-21491MedMar 10, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2021-21478MedFeb 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2021-21476MedFeb 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • CVE-2021-21444MedFeb 9, 2021
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking…

  • CVE-2020-26836MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.02

    SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as…

  • CVE-2020-26835MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-26825MedNov 13, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user…

  • CVE-2020-6367MedOct 20, 2020
    risk 0.40cvss 6.1epss 0.01

    There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no…

  • CVE-2020-6365MedOct 15, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal…

  • CVE-2020-6323MedOct 15, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in…

  • CVE-2020-6319MedOct 15, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successful exploitation an attacker…

  • CVE-2020-6324MedSep 9, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available…

  • CVE-2020-6283MedSep 9, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the…

  • CVE-2020-6281MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.

  • CVE-2020-6276MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • CVE-2020-6246MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6254MedMay 12, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

  • CVE-2020-6213MedApr 24, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled…

  • CVE-2020-6217MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6215MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL…

  • CVE-2020-6211MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.

  • CVE-2020-6229MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6224MedApr 14, 2020
    risk 0.40cvss 6.2epss 0.01

    SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to…

  • CVE-2020-6223MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application,…

  • CVE-2020-6216MedApr 14, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6210MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6205MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or…

Page 19 of 40