CVE-2023-29110
- EPSS 0.42%
- Veröffentlicht 11.04.2023 04:16:07
- Zuletzt bearbeitet 21.11.2024 07:56:34
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as he...
CVE-2023-29109
- EPSS 0.42%
- Veröffentlicht 11.04.2023 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:56:33
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas...
CVE-2021-33701
- EPSS 1.25%
- Veröffentlicht 15.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:09:24
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged ...
CVE-2018-2484
- EPSS 0.49%
- Veröffentlicht 08.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:54
SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an au...
CVE-2018-2419
- EPSS 0.18%
- Veröffentlicht 09.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:46
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.