VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2021-40495MedOct 12, 2021
    risk 0.35cvss 5.3epss 0.01

    There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP…

  • CVE-2021-33696MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from…

  • CVE-2021-38164MedSep 14, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be…

  • CVE-2021-33686MedSep 14, 2021
    risk 0.35cvss 5.3epss 0.01

    Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree.

  • CVE-2021-33679MedSep 14, 2021
    risk 0.35cvss 5.4epss 0.00

    The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in…

  • CVE-2021-33684MedJul 14, 2021
    risk 0.35cvss 5.3epss 0.01

    SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT,…

  • CVE-2021-33682MedJul 14, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious script on SAP Lumira Server. The execution of the script…

  • CVE-2021-33665MedJun 9, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2021-33664MedJun 9, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2021-33663MedJun 9, 2021
    risk 0.35cvss 5.3epss 0.01

    SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext…

  • CVE-2021-27615MedJun 9, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTTP response. The lack of these headers in response can be exploited by the attacker to execute Cross-Site Scripting (XSS) attacks.

  • CVE-2021-27601MedApr 13, 2021
    risk 0.35cvss 5.4epss 0.00

    SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify…

  • CVE-2021-27600MedApr 13, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parameter and send it to the server because SAP Manufacturing Execution (System Rules) tab does not sufficiently encode some parameters,…

  • CVE-2021-27598MedApr 13, 2021
    risk 0.35cvss 5.3epss 0.01

    SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

  • CVE-2021-21447MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into the custom value input field of an Input Control, which can be executed by User who views the relevant application content, which…

  • CVE-2021-21445MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead…

  • CVE-2020-26834MedDec 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated username for…

  • CVE-2020-26811MedNov 10, 2020
    risk 0.35cvss 5.3epss 0.02

    SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads…

  • CVE-2020-26809MedNov 10, 2020
    risk 0.35cvss 5.3epss 0.02

    SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of…

  • CVE-2020-6368MedOct 15, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate…

  • CVE-2020-6272MedOct 15, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web…

  • CVE-2020-6326MedSep 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored…

  • CVE-2020-6312MedSep 9, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to…

  • CVE-2020-6288MedSep 9, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file (including script files) without proper file format validation leading to Unrestricted upload of file with dangerous type…

  • CVE-2020-6278MedJul 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting

  • CVE-2020-6267MedJul 14, 2020
    risk 0.35cvss 5.4epss 0.01

    Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

  • CVE-2020-6261MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.

  • CVE-2020-6266MedJun 10, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.

  • CVE-2020-6260MedJun 10, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.

  • CVE-2020-6257MedMay 12, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

  • CVE-2020-6212MedApr 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing…

  • CVE-2020-6232MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

  • CVE-2020-6231MedApr 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6226MedApr 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6222MedApr 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6221MedApr 14, 2020
    risk 0.35cvss 5.4epss 0.01

    Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2020-6200MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.01

    The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.

  • CVE-2020-6199MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.00

    The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker…

  • CVE-2020-6178MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.

  • CVE-2020-6189MedFeb 12, 2020
    risk 0.35cvss 5.3epss 0.01

    Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information Disclosure.

  • CVE-2020-6185MedFeb 12, 2020
    risk 0.35cvss 5.4epss 0.01

    Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.

  • CVE-2020-6303MedJan 14, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.

  • CVE-2019-0395MedDec 11, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.

  • CVE-2019-0388MedNov 13, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

  • CVE-2019-0382MedNov 13, 2019
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.

  • CVE-2019-0379MedOct 8, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check

  • CVE-2019-0378MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file name of the background image resulting in Stored Cross-Site…

  • CVE-2019-0377MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.

  • CVE-2019-0376MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in the publication name, which can be executed later by the…

  • CVE-2019-0375MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog box of the report name resulting in reflected Cross-Site…

Page 24 of 40