Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-36920 Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP products
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.
network
low complexity
sap CWE-1021
6.1
2023-10-10 CVE-2023-40310 Unspecified vulnerability in SAP Powerdesigner 16.7
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source.
network
low complexity
sap
7.5
2023-10-10 CVE-2023-41365 Unspecified vulnerability in SAP Business ONE 10.0
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure.
network
low complexity
sap
4.3
2023-10-10 CVE-2023-42473 Unspecified vulnerability in SAP S/4Hana 106
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.
network
low complexity
sap
5.4
2023-10-10 CVE-2023-42474 Cross-site Scripting vulnerability in SAP Businessobjects web Intelligence 420
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack.
network
low complexity
sap CWE-79
5.4
2023-10-10 CVE-2023-42475 Unspecified vulnerability in SAP S/4Hana
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
network
low complexity
sap
4.3
2023-10-10 CVE-2023-42477 Unspecified vulnerability in SAP Netweaver Application Server Java 7.50
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
network
low complexity
sap
6.5
2023-09-28 CVE-2023-40307 Unspecified vulnerability in SAP Privileges
An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application.
local
low complexity
sap
7.8
2023-09-12 CVE-2023-40309 Unspecified vulnerability in SAP products
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap
critical
9.8
2023-09-12 CVE-2023-40621 Unspecified vulnerability in SAP Powerdesigner 16.7
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user.
network
low complexity
sap
6.3