Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2021-04-13 CVE-2021-27605 Missing Authorization vulnerability in SAP Fiori Apps 2.0 for Travel Management in SAP ERP
SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges.
network
low complexity
sap CWE-862
4.3
2021-04-13 CVE-2021-27603 Unspecified vulnerability in SAP Netweaver Application Server Abap 731/740/750
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time.
network
low complexity
sap
6.5
2021-04-13 CVE-2021-27602 Code Injection vulnerability in SAP Commerce
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application.
network
low complexity
sap CWE-94
critical
9.9
2021-04-13 CVE-2021-27601 Cross-site Scripting vulnerability in SAP Netweaver Application Server Java
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server.
network
low complexity
sap CWE-79
5.4
2021-04-13 CVE-2021-27600 Cross-site Scripting vulnerability in SAP Manufacturing Execution
SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parameter and send it to the server because SAP Manufacturing Execution (System Rules) tab does not sufficiently encode some parameters, resulting in Stored Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
5.4
2021-04-13 CVE-2021-27598 Missing Authorization vulnerability in SAP Netweaver Application Server Java 7.31/7.40/7.50
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc.
network
low complexity
sap CWE-862
5.3
2021-04-13 CVE-2021-21492 Authentication Bypass by Spoofing vulnerability in SAP Netweaver Application Server Java
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
network
low complexity
sap CWE-290
4.3
2021-04-13 CVE-2021-21485 Unspecified vulnerability in SAP Netweaver Application Server Java
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.
network
low complexity
sap
6.5
2021-04-13 CVE-2021-21483 Unspecified vulnerability in SAP Solution Manager 7.20
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.
network
low complexity
sap
4.9
2021-04-13 CVE-2021-21482 Unspecified vulnerability in SAP Netweaver Master Data Management 7.10.750/710
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method.
low complexity
sap
8.3