VYPR

Vendor CVEs

SAP

All CVEs

1,962 total · sorted by risk
  • CVE-2025-43000HigMay 13, 2025
    risk 0.51cvss 7.9epss 0.00

    Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.

  • CVE-2025-0069HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active…

  • CVE-2023-36923HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2023-33990HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an…

  • CVE-2023-2827HigJun 13, 2023
    risk 0.51cvss 7.9epss 0.00

    SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the…

  • CVE-2022-41202HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41201HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces…

  • CVE-2022-41200HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic (.svg, svg.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41199HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41198HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41197HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the…

  • CVE-2022-41196HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41195HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-41194HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable…

  • CVE-2022-41193HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41192HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable…

  • CVE-2022-41191HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41190HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41189HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41188HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily…

  • CVE-2022-41187HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41186HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, a Remote Code Execution can be triggered when payload forces a stack-based…

  • CVE-2022-41185HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-41184HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41180HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-41179HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41177HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be…

  • CVE-2022-41175HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41172HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-41170HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41168HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-41167HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a…

  • CVE-2022-39808HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload…

  • CVE-2022-39806HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Drawing (.slddrw, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-39805HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated Computer Graphics Metafile (.cgm, CgmTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-39804HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Part (.sldprt, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-39803HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when…

  • CVE-2022-35292HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTEM privileges. If the service is exploited by adversaries,…

  • CVE-2022-31591HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service

  • CVE-2022-31590HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated…

  • CVE-2022-28214HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and…

  • CVE-2022-24396HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.01

    The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged…

  • CVE-2022-22528HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privilege escalation on…

  • CVE-2021-40503HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the…

  • CVE-2021-33700HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.00

    SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim without knowing his/her password. The attacker could so obtain highly sensitive information which the attacker could use to take…

  • CVE-2021-33669HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality…

  • CVE-2021-27616HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted,…

  • CVE-2021-27613HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted,…

  • CVE-2021-27592HigMar 9, 2021
    risk 0.51cvss 7.8epss 0.01

    When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

  • CVE-2021-27591HigMar 9, 2021
    risk 0.51cvss 7.8epss 0.01

    When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

Page 8 of 40