CVE-2025-42894
- EPSS 0.08%
- Veröffentlicht 11.11.2025 00:19:22
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the ...
CVE-2025-42893
- EPSS 0.08%
- Veröffentlicht 11.11.2025 00:17:34
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful explo...
CVE-2025-42892
- EPSS 1.44%
- Veröffentlicht 11.11.2025 00:17:18
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this conte...
CVE-2025-42886
- EPSS 0.15%
- Veröffentlicht 11.11.2025 00:14:33
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is p...
CVE-2024-30214
- EPSS 0.15%
- Veröffentlicht 09.04.2024 01:15:49
- Zuletzt bearbeitet 21.11.2024 09:11:27
The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under certain circumstances, if the parameter contains a JavaScript, the script could be pr...
CVE-2024-30215
- EPSS 0.15%
- Veröffentlicht 09.04.2024 01:15:49
- Zuletzt bearbeitet 21.11.2024 09:11:27
The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In a successful attack, some information could be obtained and/or modified. However, the attacker does...
- EPSS 6.02%
- Veröffentlicht 16.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
CVE-2006-0732
- EPSS 3.08%
- Veröffentlicht 16.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Detail...