SAP_SE

283 tracked vulnerabilities.

CVE-2024-44120 MEDIUM
SAP NetWeaver Enterprise Portal - XSS
Sep 10, 2024
CVSS 4.7
EPSS 0.01
CVE-2024-44117 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Missing Authorization in RFC Function Module
Sep 10, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-45286 MEDIUM
SAP Production and Revenue Accounting - Info Disclosure
Sep 10, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-44116 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Missing Authorization in RFC Function Module
Sep 10, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-44115 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Missing Authorization in RFC Function Module
Sep 10, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-44113 MEDIUM
SAP Business Warehouse - Info Disclosure
Sep 10, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-42380 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Missing Authorization in RFC Function Module
Sep 10, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-42378 MEDIUM
SAP S/4HANA eProcurement - Reflected Cross-Site Scripting via Weak Input Encoding
Sep 10, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-42371 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Missing Authorization in RFC Function Module
Sep 10, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-41729 MEDIUM
SAP NetWeaver BW (BEx Analyzer) - Authenticated Information Disclosure via Missing Authorization Checks
Sep 10, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39596 MEDIUM
SAP Enable Now - Missing Authorization
Jul 09, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-39597 HIGH
SAP Commerce HY_COM 2205 and COM_CLOUD 2211 - Improper Authorization via Forgotten Password Functionality
Jul 09, 2024
CVSS 7.2
EPSS 0.00
CVE-2024-37178 MEDIUM
SAP Financial Consolidation - Cross-Site Scripting
Jun 11, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-37177 HIGH
SAP Financial Consolidation - Info Disclosure
Jun 11, 2024
CVSS 8.1
EPSS 0.00
CVE-2024-4139 MEDIUM
Manage Bank Statement ReProcessing Rules - Privilege Escalation
May 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-4138 MEDIUM
Manage Bank Statement ReProcessing Rules - Privilege Escalation
May 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-33009 MEDIUM
SAP Global Label Management - SQL Injection
May 14, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-33008 MEDIUM
SAP Replication Server - Memory Corruption
May 14, 2024
CVSS 4.9
EPSS 0.00
CVE-2024-33007 LOW
SAPUI5 PDFViewer - Embedded JavaScript Execution
May 14, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-33006 CRITICAL
SAP NetWeaver ABAP Platform - Unauthenticated Dangerous File Upload
May 14, 2024
CVSS 9.6
EPSS 0.01
CVE-2024-33002 MEDIUM
SAP S/4HANA Document Service Handler for DPS - Cross-Site Scripting
May 14, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-33000 LOW
SAP Bank Account Management - Privilege Escalation
May 14, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-32733 MEDIUM
SAP NetWeaver Application Server ABAP/ABAP Platform - XSS
May 14, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-32731 MEDIUM
SAP My Travel Requests - Privilege Escalation
May 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-32730 MEDIUM
SAP Enable Now Manager - Privilege Escalation
May 14, 2024
CVSS 6.5
EPSS 0.00