Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Total 1494 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31596 1 Sap 1 Business Objects Business Intelligence Platform 2025-04-22 N/A 6.0 MEDIUM
Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database. A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.
CVE-2017-10701 1 Sap 1 Enterprise Portal 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Security Notes 2469860, 2471209, and 2488516.
CVE-2017-9845 1 Sap 1 Netweaver 2025-04-20 7.8 HIGH 7.5 HIGH
disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.
CVE-2017-5997 1 Sap 1 Sap Kernel 2025-04-20 5.0 MEDIUM 7.5 HIGH
The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.
CVE-2017-16685 1 Sap 1 Business Warehouse Universal Data Integration 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs.
CVE-2017-15294 1 Sap 1 Customer Relationship Management 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2017-15295 1 Sap 1 Point Of Sale Xpress Server 2025-04-20 10.0 HIGH 9.8 CRITICAL
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
CVE-2017-15297 1 Sap 1 Host Agent 2025-04-20 5.0 MEDIUM 7.5 HIGH
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
CVE-2017-16690 1 Sap 1 Plant Connectivity 2025-04-20 6.8 MEDIUM 7.8 HIGH
A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possible that SAPSetup / NwSapSetup.exe loads system DLLs like DWMAPI.dll (located in your Syswow64 / System32 folder) from the folder the executable is in and not from the system location. The desired behavior is that system dlls are only loaded from the system folders. If a dll with the same name as the system dll is located in the same folder as the executable, this dll is loaded and code is executed.
CVE-2017-11458 1 Sap 1 Netweaver Application Server Java 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
CVE-2017-8913 1 Sap 1 Netweaver Application Server Java 2025-04-20 6.5 MEDIUM 8.8 HIGH
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.
CVE-2016-10079 1 Sap 1 Saplpd 2025-04-20 5.0 MEDIUM 7.5 HIGH
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.
CVE-2017-11460 1 Sap 1 Netweaver Portal 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535.
CVE-2017-16687 1 Sap 1 Hana Database 2025-04-20 5.0 MEDIUM 5.3 MEDIUM
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid.
CVE-2016-6256 1 Sap 1 Business One 2025-04-20 6.8 MEDIUM 9.6 CRITICAL
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.
CVE-2017-15296 1 Sap 1 Customer Relationship Management 2025-04-20 6.8 MEDIUM 8.8 HIGH
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVE-2017-9844 1 Sap 1 Netweaver 2025-04-20 7.5 HIGH 9.8 CRITICAL
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804.
CVE-2017-9843 1 Sap 1 Netweaver Abap 2025-04-20 4.0 MEDIUM 2.7 LOW
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.
CVE-2017-11459 1 Sap 1 Trex 2025-04-20 7.5 HIGH 9.8 CRITICAL
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.
CVE-2017-16684 1 Sap 1 Business Intelligence Promotion Management Application 2025-04-20 7.5 HIGH 9.8 CRITICAL
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity.