CVE-2023-36922
- EPSS 0.17%
- Published 11.07.2023 03:15:10
- Last modified 21.11.2024 08:10:55
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On su...
CVE-2023-32114
- EPSS 0.06%
- Published 13.06.2023 03:15:09
- Last modified 21.11.2024 08:02:44
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the serve...
CVE-2023-33984
- EPSS 0.43%
- Published 13.06.2023 03:15:09
- Last modified 21.11.2024 08:06:20
SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant...
CVE-2023-33985
- EPSS 0.4%
- Published 13.06.2023 03:15:09
- Last modified 21.11.2024 08:06:21
SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitat...
CVE-2023-29186
- EPSS 23.3%
- Published 11.04.2023 04:16:08
- Last modified 21.11.2024 07:56:40
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrativ...
CVE-2023-27499
- EPSS 0.42%
- Published 11.04.2023 03:15:07
- Last modified 21.11.2024 07:53:01
SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability....
CVE-2023-0021
- EPSS 0.83%
- Published 14.03.2023 05:15:28
- Last modified 21.11.2024 07:36:24
Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site sc...
CVE-2022-28217
- EPSS 0.26%
- Published 13.06.2022 17:15:10
- Last modified 21.11.2024 06:56:58
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks t...
CVE-2022-28772
- EPSS 1.14%
- Published 12.04.2022 17:15:10
- Last modified 21.11.2024 06:57:54
By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, ...
CVE-2022-28773
- EPSS 1.14%
- Published 12.04.2022 17:15:10
- Last modified 21.11.2024 06:57:54
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.