VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2025-42891MedDec 9, 2025
    risk 0.36cvss 5.5epss 0.00

    Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is…

  • CVE-2025-42888MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability.

  • CVE-2025-42947MedJul 23, 2025
    risk 0.36cvss 5.5epss 0.00

    SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no…

  • CVE-2025-42979MedJul 8, 2025
    risk 0.36cvss 5.6epss 0.00

    The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access…

  • CVE-2025-42996MedJun 10, 2025
    risk 0.36cvss 5.6epss 0.00

    SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of…

  • CVE-2024-37176MedJun 11, 2024
    risk 0.36cvss 5.5epss 0.00

    SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data…

  • CVE-2024-32731MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the…

  • CVE-2023-40624MedSep 12, 2023
    risk 0.36cvss 5.5epss 0.00

    SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could…

  • CVE-2022-41205MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.

  • CVE-2022-41183MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to…

  • CVE-2022-41182MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes…

  • CVE-2022-41181MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily…

  • CVE-2022-41178MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes…

  • CVE-2022-41176MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the…

  • CVE-2022-41174MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable…

  • CVE-2022-41173MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to…

  • CVE-2022-41171MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable…

  • CVE-2022-41169MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily…

  • CVE-2022-41166MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily…

  • CVE-2022-39807MedOct 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated SolidWorks Drawing (.sldasm, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily…

  • CVE-2022-35171MedJul 12, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their…

  • CVE-2022-32243MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32242MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32241MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32240MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32239MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32238MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32237MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32236MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-32235MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.01

    When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2022-28774MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

  • CVE-2021-44234MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.00

    SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

  • CVE-2021-40498MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, which can lead to denial of service.…

  • CVE-2015-7731MedAug 9, 2021
    risk 0.36cvss 5.5epss 0.00

    SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.

  • CVE-2021-33661MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-33660MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-33659MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-27643MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-27642MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-27641MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-27640MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-27639MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input…

  • CVE-2021-27638MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input…

  • CVE-2020-6315MedOct 20, 2020
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious file into the VE viewer, leading to Information Disclosure.

  • CVE-2020-6376MedOct 15, 2020
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is…

  • CVE-2020-6375MedOct 15, 2020
    risk 0.36cvss 5.5epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application,…

  • CVE-2019-0381MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.00

    A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

  • CVE-2019-0314MedJun 12, 2019
    risk 0.36cvss 5.5epss 0.01

    SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2019-0291MedMay 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.

  • CVE-2019-0256MedFeb 15, 2019
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted.

Page 22 of 40