sap
1,568 tracked vulnerabilities.
CVE-2024-37180
MEDIUM
SAP Basis - Unauthenticated Exposure of Sensitive Information via Remote-Enabled Function Module
Jul 09, 2024
CVSS 4.1
EPSS 0.00
CVE-2024-37175
MEDIUM
SAP CRM WebClient UI - Missing Authorization Check
Jul 09, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-37172
MEDIUM
SAP S/4HANA Finance - Authenticated Privilege Escalation via Advanced Payment Management
Jul 09, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-37171
MEDIUM
SAP Transportation Management Collaboration Portal - Server-Side Request Forgery
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-34692
LOW
SAP Enable Now - Authenticated Unrestricted Upload of Executable Files
Jul 09, 2024
CVSS 3.3
EPSS 0.01
CVE-2024-34689
MEDIUM
SAP Business Workflow WebFlow - Authenticated Internal Endpoint Enumeration
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-39598
MEDIUM
SAP CRM WebClient UI Framework - Authenticated Server-Side Request Forgery
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-39593
MEDIUM
SAP Landscape Management - Authenticated Exposure of Sensitive Information via REST Provider Definition Response
Jul 09, 2024
CVSS 6.9
EPSS 0.00
CVE-2024-39592
HIGH
SAP S4CORE - Missing Authorization Leading to Privilege Escalation
Jul 09, 2024
CVSS 7.7
EPSS 0.00
CVE-2024-37174
MEDIUM
SAP Customer Relationship Management WebClient UI - Cross-Site Scripting via Custom CSS Support
Jul 09, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-37173
MEDIUM
SAP CRM WebClient UI - Unauthenticated Stored Cross-Site Scripting via Crafted URL
Jul 09, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-34685
MEDIUM
SAP NetWeaver Knowledge Management and Collaboration (KMC-CM) - Stored Cross-Site Scripting in XMLEditor
Jul 09, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-37176
MEDIUM
SAP BW/4HANA - Authenticated Privilege Escalation via Improper Authorization Checks in DTP
Jun 11, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-34691
MEDIUM
SAP S/4HANA - Missing Authorization in Manage Incoming Payment Files
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-34690
MEDIUM
SAP Student Life Cycle Management - Missing Authorization
Jun 11, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-34688
HIGH
SAP NetWeaver AS Java - Denial of Service via Meta Model Repository Services
Jun 11, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-34686
MEDIUM
SAP Customer Relationship Management WebClient UI - Unauthenticated Stored Cross-Site Scripting via Crafted URL
Jun 11, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-34684
LOW
SAP BusinessObjects Business Intelligence Platform - Authenticated Local Account Password Exposure
Jun 11, 2024
CVSS 3.7
EPSS 0.00
CVE-2024-34683
MEDIUM
SAP Document Builder - Authenticated Unrestricted Upload of File with Dangerous Type
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-33001
MEDIUM
SAP NetWeaver and ABAP Platform - Denial of Service
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-28164
MEDIUM
SAP NetWeaver AS Java - Unauthenticated Exposure of Sensitive Information via CAF Guided Procedures
Jun 11, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-34687
MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Cross-Site Scripting
May 14, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-33004
MEDIUM
SAP Business Objects - Info Disclosure
May 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28165
HIGH
SAP BusinessObjects Business Intelligence Platform - Stored Cross-Site Scripting via Opendocument URL Parameter
May 14, 2024
CVSS 8.1
EPSS 0.00
CVE-2024-27898
MEDIUM
SAP NetWeaver - Server-Side Request Forgery via Crafted Request
Apr 09, 2024
CVSS 5.3
EPSS 0.00
Products
3d_visual_enterprise_viewer 131
netweaver 102
netweaver_application_server_abap 78
businessobjects_business_intelligence_platform 73
netweaver_application_server_java 68
businessobjects_business_intelligence 45
hana 38
solution_manager 33
business_one 31
internet_graphics_server 28
3d_visual_enterprise_author 27
businessobjects 23
netweaver_abap 21
netweaver_process_integration 21
netweaver_enterprise_portal 20
business_objects_business_intelligence_platform 18
commerce_cloud 18
hana_extended_application_services 18
sap_basis 18
s\/4hana 17
disclosure_management 16
host_agent 15
adaptive_server_enterprise 14
enable_now 14
s4core 13
abap_platform 12
customer_relationship_management_webclient_ui 12
netweaver_as_abap 12
sap_db 12
sap_kernel 11
Quick Filters