Vulnerabilities > SAP > Business Planning AND Consolidation > 200

DATE CVE VULNERABILITY TITLE RISK
2023-02-14 CVE-2023-23851 Unspecified vulnerability in SAP Business Planning and Consolidation 200/300
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation.
network
low complexity
sap
5.4
2022-12-13 CVE-2022-41268 Unspecified vulnerability in SAP Business Planning and Consolidation
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used.
network
high complexity
sap
7.5
2020-10-15 CVE-2020-6368 Cross-site Scripting vulnerability in SAP Business Planning and Consolidation
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
network
low complexity
sap CWE-79
5.4