Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-42479 Cross-site Scripting vulnerability in SAP Biller Direct 635/750
An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system.
network
low complexity
sap CWE-79
6.1
2023-12-12 CVE-2023-42481 Improper Access Control vulnerability in SAP Commerce Cloud 8.1
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place.
network
low complexity
sap CWE-284
8.1
2023-12-12 CVE-2023-49058 Path Traversal vulnerability in SAP Master Data Governance
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.
network
low complexity
sap CWE-22
5.3
2023-11-14 CVE-2023-31403 Incorrect Authorization vulnerability in SAP Business ONE 10.0
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.
low complexity
sap CWE-863
8.0
2023-11-14 CVE-2023-41366 Exposure of System Data to an Unauthorized Control Sphere vulnerability in SAP Netweaver Application Server Abap
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
network
low complexity
sap CWE-497
5.3
2023-11-14 CVE-2023-42480 Improper Restriction of Excessive Authentication Attempts vulnerability in SAP Netweaver Application Server Java 7.50
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
network
low complexity
sap CWE-307
5.3
2023-10-30 CVE-2023-36920 Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP products
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.
network
low complexity
sap CWE-1021
6.1
2023-10-10 CVE-2023-40310 Missing XML Validation vulnerability in SAP Powerdesigner 16.7
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source.
network
low complexity
sap CWE-112
7.5
2023-10-10 CVE-2023-41365 Information Exposure Through an Error Message vulnerability in SAP Business ONE 10.0
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure.
network
low complexity
sap CWE-209
4.3
2023-10-10 CVE-2023-42473 Missing Authorization vulnerability in SAP S/4Hana 106
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.
network
low complexity
sap CWE-862
5.4