Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Total 1580 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39599 1 Sap 1 Sap Basis 2026-06-17 N/A 4.7 MEDIUM
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidentiality, integrity, and availability.
CVE-2024-39598 1 Sap 2 Customer Relationship Management S4fnd, Customer Relationship Management Webclient Ui 2026-06-17 N/A 5.0 MEDIUM
SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
CVE-2024-39595 1 Sap 2 Business Warehouse, Business Warehouse Virtual Comp 2026-06-17 N/A 5.4 MEDIUM
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.
CVE-2024-39594 1 Sap 2 Business Warehouse, Business Warehouse Virtual Comp 2026-06-17 N/A 6.1 MEDIUM
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application.
CVE-2024-39593 1 Sap 1 Landscape Management 2026-06-17 N/A 6.9 MEDIUM
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.
CVE-2024-39592 1 Sap 2 S4core, S4coreop 2026-06-17 N/A 7.7 HIGH
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.
CVE-2024-39591 1 Sap 1 Document Builder 2026-06-17 N/A 4.3 MEDIUM
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.
CVE-2024-37180 1 Sap 1 Sap Basis 2026-06-17 N/A 4.1 MEDIUM
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.
CVE-2024-37179 1 Sap 1 Businessobjects Business Intelligence 2026-06-17 N/A 7.7 HIGH
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
CVE-2024-37176 1 Sap 1 Bw\/4hana 2026-06-17 N/A 5.5 MEDIUM
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application.
CVE-2024-37175 1 Sap 2 Customer Relationship Management S4fnd, Customer Relationship Management Webclient Ui 2026-06-17 N/A 4.3 MEDIUM
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
CVE-2024-37174 1 Sap 2 Customer Relationship Management S4fnd, Customer Relationship Management Webclient Ui 2026-06-17 N/A 6.1 MEDIUM
Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
CVE-2024-37173 1 Sap 2 Customer Relationship Management S4fnd, Customer Relationship Management Webclient Ui 2026-06-17 N/A 6.1 MEDIUM
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
CVE-2024-37172 1 Sap 2 S4core, S\/4hana 2026-06-17 N/A 5.4 MEDIUM
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.
CVE-2024-37171 1 Sap 2 Saptmui, Transportation Management 2026-06-17 N/A 5.0 MEDIUM
SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.
CVE-2024-34692 1 Sap 1 Enable Now 2026-06-17 N/A 3.3 LOW
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker can cause limited impact on confidentiality and Integrity of the application.
CVE-2024-34691 1 Sap 1 S\/4 Hana 2026-06-17 N/A 6.5 MEDIUM
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.
CVE-2024-34690 1 Sap 1 Student Life Cycle Management 2026-06-17 N/A 5.4 MEDIUM
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact on the confidentiality and integrity of the application.
CVE-2024-34689 1 Sap 2 Business Workflow, Sap Basis 2026-06-17 N/A 5.0 MEDIUM
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
CVE-2024-34688 1 Sap 1 Netweaver Application Server Java 2026-06-17 N/A 7.5 HIGH
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.