sap

1,568 tracked vulnerabilities.

CVE-2024-21736 MEDIUM
SAP S/4HANA Finance for Advanced Payment Management - Incorrect Authorization in Function Import
Jan 09, 2024
CVSS 6.4
EPSS 0.00
CVE-2024-21735 HIGH
SAP LT Replication Server S4CORE 103-108 - Incorrect Authorization
Jan 09, 2024
CVSS 7.3
EPSS 0.00
CVE-2024-21734 LOW
SAP Marketing 160 - URL Redirection to Untrusted Site via Contacts App
Jan 09, 2024
CVSS 3.7
EPSS 0.00
CVE-2023-50424 CRITICAL
SAP BTP Security Services Integration Library < 0.17.0 - Privilege Escalation
Dec 12, 2023
CVSS 9.1
EPSS 0.00
CVE-2023-6542 HIGH
SAP Emarsys SDK for Android - Unauthenticated Arbitrary URL Navigation via Activity Invocation
Dec 12, 2023
CVSS 7.1
EPSS 0.00
CVE-2023-50423 CRITICAL
SAP XSSEC < 4.1.0 - Unauthenticated Privilege Escalation
Dec 12, 2023
CVSS 9.1
EPSS 0.00
CVE-2023-50422 CRITICAL
SAP BTP Security Services Integration Library <2.17.0 and 3.0.0-<3.3.0 - Privilege Escalation
Dec 12, 2023
CVSS 9.1
EPSS 0.01
CVE-2023-49587 MEDIUM
SAP Solution Manager 720 - Authenticated Remote Code Execution via Deprecated Function Modules
Dec 12, 2023
CVSS 6.4
EPSS 0.00
CVE-2023-49584 MEDIUM
SAP Fiori launchpad - HTTP Request Smuggling via POST on Read-Only Service
Dec 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-49583 CRITICAL
SAP @sap/xssec < 3.6.0 - Unauthenticated Privilege Escalation
Dec 12, 2023
CVSS 9.1
EPSS 0.00
CVE-2023-49581 MEDIUM
SAP NetWeaver Application Server ABAP - Unauthenticated SQL Injection and Data Manipulation
Dec 12, 2023
CVSS 4.1
EPSS 0.00
CVE-2023-49580 HIGH
SAP GUI for Windows and SAP GUI for Java - Unauthenticated Information Disclosure and Layout Configuration Manipulation
Dec 12, 2023
CVSS 7.3
EPSS 0.00
CVE-2023-49578 LOW
SAP Cloud Connector 2.0 - Authenticated Denial of Service via Malicious Request
Dec 12, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-49577 MEDIUM
SAP HCM SMART PAYE S4HCMCIE 100 SAP_HRCIE 600 604 608 - Cross-Site Scripting
Dec 12, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-49058 LOW
SAP Master Data Governance File Upload - Path Traversal
Dec 12, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-42481 HIGH
SAP Commerce Cloud HY_COM 1905-2205, COM_CLOUD 2211 - Weak Password Recovery
Dec 12, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-42479 MEDIUM
SAP Biller Direct - Unauthenticated Cross-Site Scripting via URL Frame Injection
Dec 12, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-42478 HIGH
SAP Business Objects Business Intelligence Platform - Stored Cross-Site Scripting via Agnostic Document Upload
Dec 12, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-42476 MEDIUM
SAP BusinessObjects Web Intelligence 420 - Authenticated Stored Cross-Site Scripting
Dec 12, 2023
CVSS 6.8
EPSS 0.00
CVE-2023-42480 MEDIUM
SAP NetWeaver AS Java 7.50 - Unauthenticated User Enumeration via Login Brute Force
Nov 14, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-41366 MEDIUM
SAP NetWeaver Application Server ABAP - Info Disclosure
Nov 14, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-31403 CRITICAL
SAP Business One <10.0 - Auth Bypass
Nov 14, 2023
CVSS 9.6
EPSS 0.00
CVE-2023-36920 MEDIUM
SAP Enable Now - WPB_MANAGER <1.0-ENABLE_NOW_CONSUMP_DEL 1704 - XSS
Oct 30, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-42477 MEDIUM
SAP NetWeaver AS Java 7.50 - Server-Side Request Forgery in GRMG Heartbeat Application
Oct 10, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-42475 MEDIUM
SAP S/4HANA - Information Disclosure via Statutory Reporting File Storage
Oct 10, 2023
CVSS 4.3
EPSS 0.00