Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-42477 Unspecified vulnerability in SAP Netweaver Application Server Java 7.50
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
network
low complexity
sap
6.5
2023-09-12 CVE-2023-40621 Unspecified vulnerability in SAP Powerdesigner 16.7
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user.
network
low complexity
sap
6.3
2023-09-12 CVE-2023-40624 Unspecified vulnerability in SAP Netweaver Application Server Abap
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application.
network
low complexity
sap
5.4
2023-09-12 CVE-2023-40625 Unspecified vulnerability in SAP S4Core
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user.
network
low complexity
sap
5.4
2023-09-12 CVE-2023-37489 Unspecified vulnerability in SAP Businessobjects Business Intelligence 430
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity.
network
low complexity
sap
5.3
2023-09-12 CVE-2023-41367 Unspecified vulnerability in SAP Netweaver 7.50
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously.
network
low complexity
sap
5.3
2023-09-12 CVE-2023-41368 Unspecified vulnerability in SAP S/4 Hana
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.
network
low complexity
sap
5.3
2023-09-12 CVE-2023-41369 Unspecified vulnerability in SAP S/4 Hana
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
network
low complexity
sap
4.3
2023-09-08 CVE-2023-40306 Open Redirect vulnerability in SAP S/4Hana
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation.
network
low complexity
sap CWE-601
6.1
2023-08-08 CVE-2023-36926 Unspecified vulnerability in SAP Host Agent 7.22
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions.
network
low complexity
sap
5.3