VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2025-42897MedNov 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the…

  • CVE-2025-42906MedOct 14, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions,…

  • CVE-2025-42902MedOct 14, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash.…

  • CVE-2025-42926MedSep 9, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive…

  • CVE-2025-42998MedJun 10, 2025
    risk 0.34cvss 5.3epss 0.00

    The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and…

  • CVE-2025-43004MedMay 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these dashboards. Since no mechanisms exist to enforce authentication, malicious unauthenticated users…

  • CVE-2025-30011MedMay 13, 2025
    risk 0.34cvss 5.3epss 0.00

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version…

  • CVE-2025-26657MedApr 8, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability.

  • CVE-2025-23194MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of…

  • CVE-2025-23193MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no…

  • CVE-2025-23187MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

  • CVE-2025-0053MedJan 14, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the…

  • CVE-2024-47582MedDec 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

  • CVE-2024-32732MedDec 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.

  • CVE-2024-47592MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.

  • CVE-2024-41733MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker…

  • CVE-2024-28164MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.

  • CVE-2024-27898MedApr 9, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in…

  • CVE-2024-28163MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the…

  • CVE-2024-25645MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.

  • CVE-2024-25644MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

  • CVE-2024-24740MedFeb 13, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain conditions, allows an attacker to access information which could otherwise be restricted with low impact on…

  • CVE-2023-42480MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.01

    The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

  • CVE-2023-41366MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.01

    Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22,…

  • CVE-2023-41367MedSep 12, 2023
    risk 0.34cvss 5.3epss 0.01

    Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances,…

  • CVE-2023-37489MedSep 12, 2023
    risk 0.34cvss 5.3epss 0.01

    Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's…

  • CVE-2023-37487MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which could lead to high impact on confidentiality with no impact on integrity and availability of the…

  • CVE-2023-37484MedAug 8, 2023
    risk 0.34cvss 5.3epss 0.02

    SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.

  • CVE-2023-36919MedJul 11, 2023
    risk 0.34cvss 5.3epss 0.00

    In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing an unauthenticated attacker to obtain referrer details, resulting in information disclosure.

  • CVE-2023-31405MedJul 11, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any…

  • CVE-2023-29185MedApr 11, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the…

  • CVE-2023-24527MedApr 11, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a…

  • CVE-2023-27268MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to…

  • CVE-2023-26460MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.00

    Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity

  • CVE-2023-24526MedMar 14, 2023
    risk 0.34cvss 5.3epss 0.01

    SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an…

  • CVE-2022-41210MedOct 11, 2022
    risk 0.34cvss 5.2epss 0.00

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

  • CVE-2022-41209MedOct 11, 2022
    risk 0.34cvss 5.2epss 0.00

    SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

  • CVE-2022-32244MedSep 13, 2022
    risk 0.34cvss 5.2epss 0.00

    Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same…

  • CVE-2022-39014MedSep 13, 2022
    risk 0.34cvss 5.3epss 0.00

    Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be restricted.

  • CVE-2022-32248MedJul 12, 2022
    risk 0.34cvss 5.3epss 0.01

    Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.

  • CVE-2021-21316MedFeb 16, 2021
    risk 0.34cvss 6.3epss 0.01

    less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, those resources might contain JavaScript…

  • CVE-2018-2406MedApr 10, 2018
    risk 0.34cvss 5.3epss 0.00

    Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.

  • CVE-2026-34262MedApr 14, 2026
    risk 0.33cvss 5.0epss 0.00

    Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

  • CVE-2026-27688MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module…

  • CVE-2026-24317MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in…

  • CVE-2026-24313MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or…

  • CVE-2026-0486MedFeb 10, 2026
    risk 0.33cvss 5.0epss 0.00

    In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.

  • CVE-2026-0495MedJan 13, 2026
    risk 0.33cvss 5.1epss 0.00

    SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.

  • CVE-2025-42911MedSep 9, 2025
    risk 0.33cvss 5.0epss 0.00

    SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and…

  • CVE-2025-42968MedJul 8, 2025
    risk 0.33cvss 5.0epss 0.00

    SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low…

Page 26 of 40