CVE-2024-25644
- EPSS 0.38%
- Veröffentlicht 12.03.2024 01:15:49
- Zuletzt bearbeitet 10.04.2025 19:40:55
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
CVE-2024-22124
- EPSS 0.05%
- Veröffentlicht 09.01.2024 02:15:46
- Zuletzt bearbeitet 21.11.2024 08:55:37
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53,...
CVE-2023-41367
- EPSS 0.19%
- Veröffentlicht 12.09.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:10
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under ...
CVE-2023-36922
- EPSS 0.17%
- Veröffentlicht 11.07.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:55
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On su...
CVE-2023-32114
- EPSS 0.08%
- Veröffentlicht 13.06.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:44
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the serve...
CVE-2023-33984
- EPSS 0.54%
- Veröffentlicht 13.06.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:20
SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant...
CVE-2023-33985
- EPSS 0.5%
- Veröffentlicht 13.06.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:21
SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitat...
CVE-2023-29186
- EPSS 28.49%
- Veröffentlicht 11.04.2023 04:16:08
- Zuletzt bearbeitet 21.11.2024 07:56:40
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrativ...
CVE-2023-27499
- EPSS 0.53%
- Veröffentlicht 11.04.2023 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:01
SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability....
CVE-2023-0021
- EPSS 2.04%
- Veröffentlicht 14.03.2023 05:15:28
- Zuletzt bearbeitet 21.11.2024 07:36:24
Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site sc...