VYPR

Vendor CVEs

SAP

All CVEs

1,943 total · sorted by risk
  • CVE-2025-0070CriJan 14, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential…

  • CVE-2025-0066CriJan 14, 2025
    risk 0.64cvss 9.9epss 0.01

    Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an…

  • CVE-2023-40622CriSep 12, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise…

  • CVE-2023-40309CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could…

  • CVE-2023-37483CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.

  • CVE-2023-25616CriMar 14, 2023
    risk 0.64cvss 9.9epss 0.01

    In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack…

  • CVE-2023-23857CriMar 14, 2023
    risk 0.64cvss 9.9epss 0.01

    Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting…

  • CVE-2023-0022CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…

  • CVE-2023-0016CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

  • CVE-2022-41272CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to…

  • CVE-2022-41267CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on…

  • CVE-2022-35299CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.

  • CVE-2022-27668CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC…

  • CVE-2022-26100CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.

  • CVE-2022-22532CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This…

  • CVE-2021-44231CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2021-42064CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The…

  • CVE-2021-40499CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…

  • CVE-2021-38180CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to…

  • CVE-2021-37535CriSep 14, 2021
    risk 0.64cvss 9.8epss 0.01

    SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.

  • CVE-2014-9320CriAug 9, 2021
    risk 0.64cvss 9.8epss 0.04

    SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.

  • CVE-2021-27610CriJun 16, 2021
    risk 0.64cvss 9.8epss 0.01

    SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be…

  • CVE-2021-21484CriMar 9, 2021
    risk 0.64cvss 9.8epss 0.01

    LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.

  • CVE-2020-6275CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions…

  • CVE-2020-6263CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for…

  • CVE-2020-6265CriJun 9, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.

  • CVE-2020-6242CriMay 12, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate,…

  • CVE-2020-6195CriApr 14, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would give administrative…

  • CVE-2020-6198CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.

  • CVE-2011-1517CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.04

    SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

  • CVE-2019-0403CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection.

  • CVE-2019-0345CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication…

  • CVE-2019-0304CriJun 12, 2019
    risk 0.64cvss 9.8epss 0.02

    FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows…

  • CVE-2019-0261CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.04

    Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for…

  • CVE-2019-0259CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • CVE-2019-0247CriJan 8, 2019
    risk 0.64cvss 9.8epss 0.01

    SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2019-0246CriJan 8, 2019
    risk 0.64cvss 9.8epss 0.03

    SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

  • CVE-2018-2424CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.02

    SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5…

  • CVE-2018-2368CriMar 1, 2018
    risk 0.64cvss 9.8epss 0.03

    SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.

  • CVE-2017-16684CriDec 12, 2017
    risk 0.64cvss 9.8epss 0.03

    SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.

  • CVE-2017-15295CriOct 16, 2017
    risk 0.64cvss 9.8epss 0.02

    Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

  • CVE-2017-15293CriOct 16, 2017
    risk 0.64cvss 9.8epss 0.04

    Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.

  • CVE-2017-11459CriJul 25, 2017
    risk 0.64cvss 9.8epss 0.02

    SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.

  • CVE-2016-6818CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS commands via a crafted SQL…

  • CVE-2016-6143CriApr 13, 2017
    risk 0.64cvss 9.8epss 0.04

    SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

  • CVE-2017-7691CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.02

    A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

  • CVE-2016-10311CriApr 10, 2017
    risk 0.64cvss 9.8epss 0.02

    Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.

  • CVE-2017-6950CriMar 23, 2017
    risk 0.64cvss 9.8epss 0.04

    SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.

  • CVE-2016-7402CriNov 3, 2016
    risk 0.64cvss 9.8epss 0.01

    SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.

  • CVE-2016-6137CriSep 27, 2016
    risk 0.64cvss 9.8epss 0.05

    An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.

Page 2 of 39