CVE-2025-42923
- EPSS 0.02%
- Published 09.09.2025 02:15:40
- Last modified 09.09.2025 16:28:43
Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and ...
CVE-2025-42915
- EPSS 0.03%
- Published 09.09.2025 02:15:39
- Last modified 09.09.2025 16:28:43
Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confident...
CVE-2025-42941
- EPSS 0.03%
- Published 12.08.2025 02:05:27
- Last modified 12.08.2025 14:25:33
SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or mal...
CVE-2025-26660
- EPSS 0.09%
- Published 11.03.2025 01:15:35
- Last modified 11.03.2025 01:15:35
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access contro...
CVE-2025-23191
- EPSS 0.04%
- Published 11.02.2025 01:15:10
- Last modified 11.02.2025 01:15:10
Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the ...
CVE-2024-25643
- EPSS 0.15%
- Published 13.02.2024 04:15:08
- Last modified 21.11.2024 09:01:08
The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access inf...
CVE-2023-24528
- EPSS 0.14%
- Published 14.02.2023 04:15:12
- Last modified 21.11.2024 07:48:03
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network a...
CVE-2020-6266
- EPSS 0.17%
- Published 10.06.2020 13:15:18
- Last modified 21.11.2024 05:35:24
SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.
CVE-2018-2474
- EPSS 0.16%
- Published 09.10.2018 13:29:02
- Last modified 21.11.2024 04:03:52
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.