VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2024-44116MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on integrity of the…

  • CVE-2024-44115MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the…

  • CVE-2024-44113MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on…

  • CVE-2024-42380MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application.

  • CVE-2024-41729MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the…

  • CVE-2024-42373MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically…

  • CVE-2024-41734MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

  • CVE-2024-39591MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.

  • CVE-2024-42377MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application

  • CVE-2024-42375MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrity of the application.

  • CVE-2024-41736MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application.

  • CVE-2024-39596MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.

  • CVE-2024-37175MedJul 9, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.

  • CVE-2024-4139MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application.…

  • CVE-2024-4138MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of…

  • CVE-2024-33004MedMay 14, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited…

  • CVE-2024-30217MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the…

  • CVE-2024-30216MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of…

  • CVE-2024-27900MedMar 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.

  • CVE-2024-25643MedFeb 13, 2024
    risk 0.28cvss 4.3epss 0.00

    The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access information that the user should…

  • CVE-2024-24741MedFeb 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to read some sensitive…

  • CVE-2023-49584MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_BASIS 793, allows an attacker to use HTTP verb POST on read-only service causing low impact on Confidentiality of the application.

  • CVE-2023-42475MedOct 10, 2023
    risk 0.28cvss 4.3epss 0.00

    The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.

  • CVE-2023-41365MedOct 10, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the…

  • CVE-2023-1903MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.

  • CVE-2023-24525MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.00

    SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of…

  • CVE-2023-23856MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.00

    In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable…

  • CVE-2022-41273MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.00

    Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be…

  • CVE-2022-41263MedDec 12, 2022
    risk 0.28cvss 4.3epss 0.00

    Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful…

  • CVE-2022-31592MedJul 12, 2022
    risk 0.28cvss 4.3epss 0.01

    The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the network, resulting in escalation of privileges leading to a…

  • CVE-2022-29612MedJun 14, 2022
    risk 0.28cvss 4.3epss 0.01

    SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of…

  • CVE-2022-29613MedMay 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the…

  • CVE-2021-42067MedJan 14, 2022
    risk 0.28cvss 4.3epss 0.01

    In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to…

  • CVE-2021-42062MedNov 10, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability…

  • CVE-2021-40496MedOct 12, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial…

  • CVE-2021-37532MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.

  • CVE-2021-33688MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.

  • CVE-2021-33706MedAug 10, 2021
    risk 0.28cvss 4.3epss 0.01

    Due to improper input validation in InfraBox, logs can be modified by an authenticated user.

  • CVE-2021-33689MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

  • CVE-2021-33683MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73, WEBDISP 7.53, 7.73, 7.77,…

  • CVE-2021-33667MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.

  • CVE-2021-27605MedApr 13, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges. However, the attacker can only read some…

  • CVE-2021-21492MedApr 13, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

  • CVE-2021-21467MedJan 12, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper…

  • CVE-2021-21464MedJan 12, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2020-6316MedNov 10, 2020
    risk 0.28cvss 4.3epss 0.01

    SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

  • CVE-2020-6371MedOct 15, 2020
    risk 0.28cvss 4.3epss 0.01

    User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.

  • CVE-2020-6361MedSep 9, 2020
    risk 0.28cvss 4.3epss 0.02

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE files received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2020-6360MedSep 9, 2020
    risk 0.28cvss 4.3epss 0.02

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2020-6359MedSep 9, 2020
    risk 0.28cvss 4.3epss 0.02

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PLT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

Page 30 of 40