Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-42474 Cross-site Scripting vulnerability in SAP Businessobjects web Intelligence 420
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack.
network
low complexity
sap CWE-79
5.4
2023-10-10 CVE-2023-42475 Information Exposure Through an Error Message vulnerability in SAP S/4Hana
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
network
low complexity
sap CWE-209
4.3
2023-10-10 CVE-2023-42477 Server-Side Request Forgery (SSRF) vulnerability in SAP Netweaver Application Server Java 7.50
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
network
low complexity
sap CWE-918
6.5
2023-09-12 CVE-2023-40621 Code Injection vulnerability in SAP Powerdesigner 16.7
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user.
network
low complexity
sap CWE-94
6.3
2023-09-12 CVE-2023-40624 Cross-site Scripting vulnerability in SAP Netweaver Application Server Abap
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application.
network
low complexity
sap CWE-79
5.4
2023-09-12 CVE-2023-40625 Missing Authorization vulnerability in SAP S4Core
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user.
network
low complexity
sap CWE-862
5.4
2023-09-12 CVE-2023-37489 Information Exposure Through an Error Message vulnerability in SAP Businessobjects Business Intelligence 430
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity.
network
low complexity
sap CWE-209
5.3
2023-09-12 CVE-2023-41367 Missing Authentication for Critical Function vulnerability in SAP Netweaver 7.50
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously.
network
low complexity
sap CWE-306
5.3
2023-09-12 CVE-2023-41368 Authorization Bypass Through User-Controlled Key vulnerability in SAP S/4 Hana
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.
network
low complexity
sap CWE-639
5.3
2023-09-12 CVE-2023-41369 XXE vulnerability in SAP S/4 Hana
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
network
low complexity
sap CWE-611
4.3