Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2021-05-11 CVE-2021-27613 Unspecified vulnerability in SAP Chef Business-One-Cookbook 0.1.9
Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure and highly impact system confidentiality, integrity and availability.
local
low complexity
sap
7.8
2021-05-11 CVE-2021-27614 Injection vulnerability in SAP Business-One-Hana-Chef-Cookbook and Business ONE
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application.
local
low complexity
sap CWE-74
7.1
2021-05-11 CVE-2021-27616 Unspecified vulnerability in SAP Business-One-Hana-Chef-Cookbook and Business ONE
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.
local
low complexity
sap
7.8
2021-05-11 CVE-2021-27617 Improper Input Validation vulnerability in SAP Netweaver Process Integration
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source.
network
low complexity
sap CWE-20
4.9
2021-05-11 CVE-2021-27618 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Netweaver Process Integration
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source.
network
low complexity
sap CWE-434
4.9
2021-05-11 CVE-2021-27619 Unspecified vulnerability in SAP Commerce
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them.
network
low complexity
sap
6.5
2021-04-14 CVE-2021-27608 Unquoted Search Path or Element vulnerability in SAP Setup 9.0
An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered.
local
high complexity
sap CWE-428
7.5
2021-04-14 CVE-2021-27604 XXE vulnerability in SAP Netweaver Process Integration
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note.
network
low complexity
sap CWE-611
6.5
2021-04-14 CVE-2021-27599 Unspecified vulnerability in SAP Netweaver Process Integration
SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted.
network
low complexity
sap
6.5
2021-04-13 CVE-2021-27609 Missing Authorization vulnerability in SAP Focused RUN 200/300
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert service data collection and sending to SAP without the intended authorization.
network
low complexity
sap CWE-862
6.5