SAP

Fiori

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 09.09.2025 02:15:40
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and ...

  • EPSS 0.03%
  • Veröffentlicht 09.09.2025 02:15:39
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confident...

  • EPSS 0.03%
  • Veröffentlicht 12.08.2025 02:05:27
  • Zuletzt bearbeitet 12.08.2025 14:25:33

SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or mal...

  • EPSS 0.09%
  • Veröffentlicht 11.03.2025 01:15:35
  • Zuletzt bearbeitet 11.03.2025 01:15:35

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access contro...

  • EPSS 0.04%
  • Veröffentlicht 11.02.2025 01:15:10
  • Zuletzt bearbeitet 11.02.2025 01:15:10

Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the ...

  • EPSS 0.15%
  • Veröffentlicht 13.02.2024 04:15:08
  • Zuletzt bearbeitet 21.11.2024 09:01:08

The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access inf...

  • EPSS 0.14%
  • Veröffentlicht 14.02.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:03

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network a...

  • EPSS 0.17%
  • Veröffentlicht 10.06.2020 13:15:18
  • Zuletzt bearbeitet 21.11.2024 05:35:24

SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.

  • EPSS 0.16%
  • Veröffentlicht 09.10.2018 13:29:02
  • Zuletzt bearbeitet 21.11.2024 04:03:52

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.