SAP

Fiori

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 27.01.2026 00:22:13
  • Zuletzt bearbeitet 27.01.2026 14:59:34

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 13.01.2026 01:15:50
  • Zuletzt bearbeitet 13.01.2026 14:03:18

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability...

Medienbericht
  • EPSS 0.05%
  • Veröffentlicht 13.01.2026 01:13:28
  • Zuletzt bearbeitet 13.01.2026 14:03:18

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the ap...

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 13.01.2026 01:13:20
  • Zuletzt bearbeitet 13.01.2026 14:03:18

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability ...

  • EPSS 0.02%
  • Veröffentlicht 13.01.2026 01:13:06
  • Zuletzt bearbeitet 13.01.2026 14:03:18

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may all...

  • EPSS 0.03%
  • Veröffentlicht 09.09.2025 02:15:40
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and ...

  • EPSS 0.05%
  • Veröffentlicht 09.09.2025 02:15:39
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confident...

  • EPSS 0.02%
  • Veröffentlicht 12.08.2025 02:05:27
  • Zuletzt bearbeitet 12.08.2025 14:25:33

SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or mal...

  • EPSS 0.11%
  • Veröffentlicht 11.03.2025 01:15:35
  • Zuletzt bearbeitet 11.03.2025 01:15:35

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access contro...

  • EPSS 0.08%
  • Veröffentlicht 11.02.2025 01:15:10
  • Zuletzt bearbeitet 11.02.2025 01:15:10

Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the ...