SAP

S/4hana

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 10.10.2023 02:15:11
  • Zuletzt bearbeitet 21.11.2024 08:22:37

The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.

  • EPSS 0.15%
  • Veröffentlicht 10.10.2023 02:15:10
  • Zuletzt bearbeitet 21.11.2024 08:22:37

S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.

  • EPSS 0.1%
  • Veröffentlicht 08.09.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 08:19:12

SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.

  • EPSS 0.12%
  • Veröffentlicht 14.02.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 07:48:03

SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability. ...

  • EPSS 0.21%
  • Veröffentlicht 12.07.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:06:00

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the...

  • EPSS 0.14%
  • Veröffentlicht 12.07.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:04:49

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, r...

  • EPSS 0.19%
  • Veröffentlicht 14.06.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 07:04:47

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that ...

  • EPSS 0.6%
  • Veröffentlicht 09.02.2022 23:15:18
  • Zuletzt bearbeitet 21.11.2024 06:46:59

S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private address fields of Employee Busin...

  • EPSS 0.37%
  • Veröffentlicht 14.01.2022 20:15:15
  • Zuletzt bearbeitet 21.11.2024 06:46:58

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive ...

  • EPSS 0.49%
  • Veröffentlicht 14.01.2022 20:15:15
  • Zuletzt bearbeitet 21.11.2024 06:46:58

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which c...