Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-14 CVE-2021-38150 Cleartext Storage of Sensitive Information vulnerability in SAP Business Client 7.0/7.70
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials.
network
sap CWE-312
4.3
2021-09-14 CVE-2021-38164 Missing Authorization vulnerability in SAP ERP Financial Accounting
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users.
network
low complexity
sap CWE-862
5.5
2021-09-14 CVE-2021-38174 Unspecified vulnerability in SAP 3D Visual Enterprise Viewer 9
When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
network
sap
4.3
2021-09-14 CVE-2021-38175 Information Exposure vulnerability in SAP Analysis for Microsoft Office 2.8
SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the network, and gather or change information in the current system without user interaction.
network
low complexity
sap CWE-200
5.5
2021-09-14 CVE-2021-38177 NULL Pointer Dereference vulnerability in SAP Commoncryptolib 8.4.29/8.5.38
SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the availability of the SAP system.
network
low complexity
sap CWE-476
5.0
2021-08-10 CVE-2021-33706 Improper Input Validation vulnerability in SAP Infrabox
Due to improper input validation in InfraBox, logs can be modified by an authenticated user.
network
low complexity
sap CWE-20
4.0
2021-08-10 CVE-2021-33707 Open Redirect vulnerability in SAP Netweaver Knowledge Management
SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component.
network
sap CWE-601
5.8
2021-08-09 CVE-2015-2073 Path Traversal vulnerability in SAP Businessobjects Edge 4.0
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.
network
low complexity
sap CWE-22
5.0
2021-08-09 CVE-2015-2074 Path Traversal vulnerability in SAP Businessobjects Edge 4.0
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.
network
low complexity
sap CWE-22
5.0
2021-08-09 CVE-2018-17861 Cross-site Scripting vulnerability in SAP J2Ee Engine 7.01
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol.
network
low complexity
sap CWE-79
6.1