Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2023-32111 Unspecified vulnerability in SAP Powerdesigner Proxy 16.7
In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption.
network
low complexity
sap
7.5
2023-05-09 CVE-2023-32112 Unspecified vulnerability in SAP S4Core and Vendor Master Hierarchy
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function.
local
low complexity
sap
5.5
2023-05-09 CVE-2023-32113 Unspecified vulnerability in SAP GUI for Windows
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file.
network
low complexity
sap
critical
9.3
2023-05-09 CVE-2023-28762 Unspecified vulnerability in SAP Businessobjects Business Intelligence 420/430
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction.
network
low complexity
sap
7.2
2023-05-09 CVE-2023-28764 Unspecified vulnerability in SAP Businessobjects 4.20/4.30
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network.
network
high complexity
sap
5.9
2023-05-09 CVE-2023-29188 Unspecified vulnerability in SAP products
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap
5.4
2023-04-11 CVE-2023-29110 Cross-site Scripting vulnerability in SAP products
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags.
network
low complexity
sap CWE-79
5.4
2023-04-11 CVE-2023-29111 Unspecified vulnerability in SAP Application Interface Framework 755/756
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required.
network
low complexity
sap
4.3
2023-04-11 CVE-2023-29112 Cross-site Scripting vulnerability in SAP Application Interface 600/700
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment.
network
low complexity
sap CWE-79
5.4
2023-04-11 CVE-2023-29185 Unspecified vulnerability in SAP Netweaver AS Abap Business Server Pages
SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.
network
low complexity
sap
6.5