sap

1,568 tracked vulnerabilities.

CVE-2024-37180 MEDIUM
SAP Basis - Unauthenticated Exposure of Sensitive Information via Remote-Enabled Function Module
Jul 09, 2024
CVSS 4.1
EPSS 0.00
CVE-2024-37175 MEDIUM
SAP CRM WebClient UI - Missing Authorization Check
Jul 09, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-37172 MEDIUM
SAP S/4HANA Finance - Authenticated Privilege Escalation via Advanced Payment Management
Jul 09, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-37171 MEDIUM
SAP Transportation Management Collaboration Portal - Server-Side Request Forgery
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-34692 LOW
SAP Enable Now - Authenticated Unrestricted Upload of Executable Files
Jul 09, 2024
CVSS 3.3
EPSS 0.01
CVE-2024-34689 MEDIUM
SAP Business Workflow WebFlow - Authenticated Internal Endpoint Enumeration
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-39598 MEDIUM
SAP CRM WebClient UI Framework - Authenticated Server-Side Request Forgery
Jul 09, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-39593 MEDIUM
SAP Landscape Management - Authenticated Exposure of Sensitive Information via REST Provider Definition Response
Jul 09, 2024
CVSS 6.9
EPSS 0.00
CVE-2024-39592 HIGH
SAP S4CORE - Missing Authorization Leading to Privilege Escalation
Jul 09, 2024
CVSS 7.7
EPSS 0.00
CVE-2024-37174 MEDIUM
SAP Customer Relationship Management WebClient UI - Cross-Site Scripting via Custom CSS Support
Jul 09, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-37173 MEDIUM
SAP CRM WebClient UI - Unauthenticated Stored Cross-Site Scripting via Crafted URL
Jul 09, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-34685 MEDIUM
SAP NetWeaver Knowledge Management and Collaboration (KMC-CM) - Stored Cross-Site Scripting in XMLEditor
Jul 09, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-37176 MEDIUM
SAP BW/4HANA - Authenticated Privilege Escalation via Improper Authorization Checks in DTP
Jun 11, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-34691 MEDIUM
SAP S/4HANA - Missing Authorization in Manage Incoming Payment Files
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-34690 MEDIUM
SAP Student Life Cycle Management - Missing Authorization
Jun 11, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-34688 HIGH
SAP NetWeaver AS Java - Denial of Service via Meta Model Repository Services
Jun 11, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-34686 MEDIUM
SAP Customer Relationship Management WebClient UI - Unauthenticated Stored Cross-Site Scripting via Crafted URL
Jun 11, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-34684 LOW
SAP BusinessObjects Business Intelligence Platform - Authenticated Local Account Password Exposure
Jun 11, 2024
CVSS 3.7
EPSS 0.00
CVE-2024-34683 MEDIUM
SAP Document Builder - Authenticated Unrestricted Upload of File with Dangerous Type
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-33001 MEDIUM
SAP NetWeaver and ABAP Platform - Denial of Service
Jun 11, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-28164 MEDIUM
SAP NetWeaver AS Java - Unauthenticated Exposure of Sensitive Information via CAF Guided Procedures
Jun 11, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-34687 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform - Cross-Site Scripting
May 14, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-33004 MEDIUM
SAP Business Objects - Info Disclosure
May 14, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28165 HIGH
SAP BusinessObjects Business Intelligence Platform - Stored Cross-Site Scripting via Opendocument URL Parameter
May 14, 2024
CVSS 8.1
EPSS 0.00
CVE-2024-27898 MEDIUM
SAP NetWeaver - Server-Side Request Forgery via Crafted Request
Apr 09, 2024
CVSS 5.3
EPSS 0.00