Vulnerabilities > SAP
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-09 | CVE-2023-30743 | Cross-site Scripting vulnerability in SAP Sapui5 Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. | 6.1 |
2023-05-09 | CVE-2023-30744 | Missing Authentication for Critical Function vulnerability in SAP Netweaver Application Server for Java 7.50 In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication. | 9.1 |
2023-05-09 | CVE-2023-31404 | Information Exposure vulnerability in SAP Businessobjects Business Intelligence 420/430 Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. | 5.0 |
2023-05-09 | CVE-2023-31406 | Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence 420/430 Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. | 6.1 |
2023-05-09 | CVE-2023-31407 | Cross-site Scripting vulnerability in SAP Business Planning and Consolidation 740/750 SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. | 5.4 |
2023-05-09 | CVE-2023-32111 | Out-of-bounds Write vulnerability in SAP Powerdesigner Proxy 16.7 In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. | 7.5 |
2023-05-09 | CVE-2023-32112 | Missing Authorization vulnerability in SAP S4Core and Vendor Master Hierarchy Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. | 5.5 |
2023-05-09 | CVE-2023-32113 | Information Exposure vulnerability in SAP GUI for Windows SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. | 9.3 |
2023-05-09 | CVE-2023-28762 | Unspecified vulnerability in SAP Businessobjects Business Intelligence 420/430 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. | 7.2 |
2023-05-09 | CVE-2023-28764 | Insufficiently Protected Credentials vulnerability in SAP Businessobjects 4.20/4.30 SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. | 5.9 |