VYPR

Vendor CVEs

SAP

All CVEs

1,943 total · sorted by risk
  • CVE-2021-21462HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21461HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21460HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21459HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21458HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21457HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21456HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21455HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21454HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21453HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21452HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21451HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21450HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2021-21449HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper…

  • CVE-2020-26819HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.

  • CVE-2020-26818HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing…

  • CVE-2020-6296HigAug 12, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the…

  • CVE-2020-6292HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

  • CVE-2020-6291HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

  • CVE-2020-6289HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.

  • CVE-2020-6262HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…

  • CVE-2020-6249HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

  • CVE-2020-6243HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted…

  • CVE-2020-6241HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.

  • CVE-2020-6225HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through…

  • CVE-2020-6219HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and…

  • CVE-2020-6188HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.01

    VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing…

  • CVE-2019-0384HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user…

  • CVE-2019-0383HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in…

  • CVE-2019-0398HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

  • CVE-2019-0389HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.

  • CVE-2019-0351HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.03

    A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including…

  • CVE-2019-0343HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the…

  • CVE-2019-0341HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cookie could then be abused to gain access to the application.

  • CVE-2019-0301HigMay 14, 2019
    risk 0.57cvss 8.8epss 0.01

    Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.

  • CVE-2019-0280HigMay 14, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.

  • CVE-2019-0279HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.01

    ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all circumstances for an…

  • CVE-2019-0276HigMar 12, 2019
    risk 0.57cvss 8.8epss 0.02

    Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation of privileges.

  • CVE-2019-0270HigMar 12, 2019
    risk 0.57cvss 8.8epss 0.01

    ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT,…

  • CVE-2019-0267HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.

  • CVE-2019-0258HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2019-0257HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of…

  • CVE-2019-0243HigJan 8, 2019
    risk 0.57cvss 8.8epss 0.02

    Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2018-2484HigJan 8, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting…

  • CVE-2018-2477HigNov 13, 2018
    risk 0.57cvss 8.8epss 0.02

    Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2018-2462HigSep 11, 2018
    risk 0.57cvss 8.8epss 0.02

    In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2018-2461HigSep 11, 2018
    risk 0.57cvss 8.8epss 0.01

    Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges.

  • CVE-2018-2455HigSep 11, 2018
    risk 0.57cvss 8.8epss 0.01

    SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2018-2454HigSep 11, 2018
    risk 0.57cvss 8.8epss 0.01

    SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2018-2442HigAug 14, 2018
    risk 0.57cvss 8.8epss 0.01

    In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.

Page 5 of 39