CVE-2025-42930
- EPSS 0.07%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 09.09.2025 16:28:43
SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impac...
CVE-2023-31407
- EPSS 0.31%
- Veröffentlicht 09.05.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:01:47
SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentia...
CVE-2023-23851
- EPSS 0.16%
- Veröffentlicht 14.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:46:57
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the...
CVE-2023-0016
- EPSS 0.22%
- Veröffentlicht 10.01.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:23
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the ba...
CVE-2022-41268
- EPSS 0.26%
- Veröffentlicht 13.12.2022 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:22:57
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code...
CVE-2020-6368
- EPSS 0.38%
- Veröffentlicht 15.10.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:35
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication infor...
CVE-2017-16349
- EPSS 0.33%
- Veröffentlicht 02.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:16:18
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service....