SAP SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP Cloud Connector.
Products
Clear product- SAP 3D Visual Enterprise Viewer127 vulnerabilities
- SAP 3D Visual Enterprise Author27 vulnerabilities
- SAP Business One18 vulnerabilities
- SAP Disclosure Management13 vulnerabilities
- SAP Internet Graphics Server13 vulnerabilities
- SAP Business Objects Business Intelligence Platform12 vulnerabilities
- SAP HANA Extended Application Services12 vulnerabilities
- SAP Commerce10 vulnerabilities
- SAP Enable Now10 vulnerabilities
- SAP NetWeaver Enterprise Portal10 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform9 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)9 vulnerabilities
- SAP Adaptive Server Enterprise7 vulnerabilities
- SAP Financial Consolidation7 vulnerabilities
- SAP Internet Graphics Service7 vulnerabilities
- SAP NetWeaver AS ABAP7 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform7 vulnerabilities
- SAP Cloud Connector6 vulnerabilities
- SAP HANA6 vulnerabilities
- SAP S/4HANA6 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform (BI Workspace)5 vulnerabilities
- SAP Commerce Cloud5 vulnerabilities
- SAP Host Agent5 vulnerabilities
- SAP NetWeaver (ABAP Server) and ABAP Platform5 vulnerabilities
- SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-33694MEDIUM | SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting. CWE-79Sep 15, 2021 | CVSS4.8v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33693MEDIUM | SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution. CWE-94Sep 15, 2021 | CVSS6.8v3.1 | EPSS0.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33695CRITICAL | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate. | CVSS9.1v3.1 | EPSS0.559% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33692HIGH | SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted location to access files or directories. CWE-22Sep 15, 2021 | CVSS7.5v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0247CRITICAL | SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. CWE-94Jan 8, 2019 | CVSS9.8v3.0 | EPSS1.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-0246CRITICAL | SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. CWE-306Jan 8, 2019 | CVSS9.8v3.0 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |