SAP

SAP BW

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 08.07.2025 00:35:36
  • Last modified 08.07.2025 16:18:14

SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on...

  • EPSS 0.04%
  • Published 08.07.2025 00:35:16
  • Last modified 08.07.2025 16:18:14

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table ...

Media report
  • EPSS 0.06%
  • Published 08.07.2025 00:34:32
  • Last modified 08.07.2025 16:18:14

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system u...

Media report
  • EPSS 0.06%
  • Published 10.06.2025 00:11:14
  • Last modified 12.06.2025 16:06:39

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely dele...

  • EPSS 0.1%
  • Published 10.09.2024 03:15:02
  • Last modified 10.09.2024 12:09:50

Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causin...

  • EPSS 0.1%
  • Published 09.07.2024 05:15:12
  • Last modified 21.11.2024 09:28:04

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impac...

  • EPSS 0.11%
  • Published 09.07.2024 05:15:12
  • Last modified 21.11.2024 09:28:05

SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on ...