Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-50423 Unspecified vulnerability in SAP Sap-XSSec
SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges.
network
low complexity
sap
critical
9.8
2023-12-12 CVE-2023-6542 Incorrect Authorization vulnerability in SAP Emarsys SDK 3.6.2
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application.
local
low complexity
sap CWE-863
7.1
2023-12-12 CVE-2023-42476 Unspecified vulnerability in SAP Businessobjects web Intelligence 420
SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited.
network
low complexity
sap
6.8
2023-12-12 CVE-2023-42478 Unspecified vulnerability in SAP Business Objects Business Intelligence Platform 420/430
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.
network
low complexity
sap
7.6
2023-12-12 CVE-2023-42479 Unspecified vulnerability in SAP Biller Direct 635/750
An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system.
network
low complexity
sap
6.1
2023-12-12 CVE-2023-42481 Unspecified vulnerability in SAP Commerce Cloud 8.1
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place.
network
low complexity
sap
8.1
2023-12-12 CVE-2023-49058 Unspecified vulnerability in SAP Master Data Governance
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs.
network
low complexity
sap
5.3
2023-11-14 CVE-2023-31403 Unspecified vulnerability in SAP Business ONE 10.0
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.
low complexity
sap
8.0
2023-11-14 CVE-2023-41366 Unspecified vulnerability in SAP Netweaver Application Server Abap
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
network
low complexity
sap
5.3
2023-11-14 CVE-2023-42480 Unspecified vulnerability in SAP Netweaver Application Server Java 7.50
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
network
low complexity
sap
5.3