Vulnerabilities > SAP > S 4 Hana > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-09 CVE-2020-26832 Missing Authorization vulnerability in SAP Netweaver Application Server Abap and S/4 Hana
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.
network
low complexity
sap CWE-862
7.6
2020-02-12 CVE-2020-6188 Missing Authorization vulnerability in SAP ERP and S/4 Hana
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.
network
low complexity
sap CWE-862
8.8