CVE-2023-29110
- EPSS 0.34%
- Published 11.04.2023 04:16:07
- Last modified 21.11.2024 07:56:34
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as he...
CVE-2023-29109
- EPSS 0.34%
- Published 11.04.2023 03:15:07
- Last modified 21.11.2024 07:56:33
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas...
CVE-2022-41264
- EPSS 0.58%
- Published 13.12.2022 03:15:09
- Last modified 21.11.2024 07:22:56
Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public ...
CVE-2020-6307
- EPSS 0.24%
- Published 14.01.2020 18:15:12
- Last modified 21.11.2024 05:35:28
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
CVE-2019-0248
- EPSS 0.39%
- Published 08.01.2019 20:29:00
- Last modified 21.11.2024 04:16:34
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.
CVE-2018-2478
- EPSS 0.37%
- Published 13.11.2018 20:29:00
- Last modified 21.11.2024 04:03:53
An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be execut...