- EPSS 0.72%
- Veröffentlicht 14.09.2021 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:16:34
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On succ...
CVE-2020-6316
- EPSS 0.15%
- Veröffentlicht 10.11.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:35:29
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.
CVE-2020-6212
- EPSS 0.13%
- Veröffentlicht 24.04.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:18
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an aut...
CVE-2020-6214
- EPSS 0.2%
- Veröffentlicht 14.04.2020 19:15:16
- Zuletzt bearbeitet 21.11.2024 05:35:18
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authentica...
CVE-2020-6185
- EPSS 0.27%
- Veröffentlicht 12.02.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:15
Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Si...
CVE-2020-6184
- EPSS 0.54%
- Veröffentlicht 12.02.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:15
Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Script...