We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 1214 and the highest CVSS score is 10.0.

 

3692004
CVSS
6.1

Affected system type SAP NetWeaver...
Patchday 2026-07
Released on 2026/04/14
Description 3692004 - [CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
3747787
CVSS
10.0

Affected system type BTP
Patchday 2026-06
Released on 2026/04/29
Description 3747787 - Malicious open-source packages in SAP Cloud Application Programming Model & MTA Build Tool
3746332
CVSS
9.9

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3746332 - [CVE-2026-44748] XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform
3717897
CVSS
9.8

Affected system type Kernel / ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3717897 - [CVE-2026-27671] Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
3733064
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/05/12
Description 3733064 - [CVE-2026-34263] Missing authentication check in SAP Commerce Cloud configuration
3748262
CVSS
9.1

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3748262 - [CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub
3747484
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-06
Released on 2026/06/09
Description 3747484 - [CVE-2026-29145] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3735546
CVSS
7.1

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3735546 - [CVE-2026-44751] Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform
3748819
CVSS
6.6

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3748819 - [CVE-2026-44754] Missing caller identification check-in for ODP Data Replication APIs
3751691
CVSS
6.5

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3751691 - [CVE-2026-44744] SQL Injection vulnerability in SAP S/4HANA
3723655
CVSS
6.1

Affected system type Java
Patchday 2026-06
Released on 2026/06/09
Description 3723655 - [CVE-2026-44746] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Servlet)
3715280
CVSS
4.7

Affected system type SAP Solution Manager
Patchday 2026-06
Released on 2026/06/09
Description 3715280 - [CVE-2026-44757] Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager
3673181
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/06/09
Description 3673181 - [CVE-2026-44750] Missing Authorization check in SAP MDG (Review Match Groups Application)
3687096
CVSS
4.3

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3687096 - [CVE-2026-44755] Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform
3433366
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/26
Description 3433366 - [CVE-2026-44749] Information Disclosure vulnerability in SAP Gateway
3718508
CVSS
4.3

Affected system type ABAP
Patchday 2026-06
Released on 2026/05/12
Description 3718508 - [CVE-2026-40134] Missing Authorization Check in SAP Incentive and Commission Management
3706000
CVSS
3.7

Affected system type BI/BO platform
Patchday 2026-06
Released on 2026/06/09
Description 3706000 - [CVE-2026-44743] Security Misconfiguration vulnerability in SAP Business Objects
3724838
CVSS
9.6

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3724838 - [CVE-2026-34260] SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP)
3730019
CVSS
6.5

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3730019 - [CVE-2026-40135] OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3718083
CVSS
6.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3718083 - [CVE-2026-40133] Missing Authorization check in SAP S/4HANA Condition Maintenance
3727717
CVSS
6.1

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3727717 - [CVE-2026-40137] Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3721959
CVSS
5.4

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3721959 - [CVE-2026-40132] Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
3667593
CVSS
5.4

Affected system type BI/BO platform
Patchday 2026-05
Released on 2026/05/12
Description 3667593 - [CVE-2026-0502] Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform
3716450
CVSS
4.8

Affected system type SAP Commerce Cloud
Patchday 2026-05
Released on 2026/05/12
Description 3716450 - [CVE-2025-68161] Potential Improper Certificate Validation in SAP Commerce Cloud (Apache Log4j)
3726583
CVSS
4.7

Affected system type SAP UI5
Patchday 2026-05
Released on 2026/05/12
Description 3726583 - [CVE-2026-34258] Content Spoofing vulnerability in SAPUI5 (Search UI)
3728690
CVSS
4.7

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3728690 - [CVE-2026-27682] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
3713521
CVSS
4.3

Affected system type SAP Financial Consolidation
Patchday 2026-05
Released on 2026/05/12
Description 3713521 - [CVE-2026-40136] Denial of service (DoS) in SAP Financial Consolidation
3735359
CVSS
4.3

Affected system type ABAP
Patchday 2026-05
Released on 2026/05/12
Description 3735359 - [CVE-2026-40129] Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
3726962
CVSS
3.4

Affected system type HANA platform
Patchday 2026-05
Released on 2026/05/12
Description 3726962 - [CVE-2026-40131] SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library
3719353
CVSS
9.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3719353 - [CVE-2026-27681] SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
3678282
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/02/10
Description 3678282 - [CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
3731908
CVSS
7.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3731908 - [CVE-2026-34256] Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
3716767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3716767 - [CVE-2026-27679] Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures)
3680767
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3680767 - [CVE-2026-34264] Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA
3696239
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3696239 - [CVE-2025-64775] Denial of Service Vulnerability in SAP BusinessObjects Business Intelligence Platform
3715097
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715097 - [CVE-2026-27677] Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment)
3715177
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3715177 - [CVE-2026-27678] Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures)
3705094
CVSS
6.5

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3705094 - [CVE-2026-34261] Missing Authorization check in SAP Business Analytics and SAP Content Management
3689080
CVSS
6.4

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3689080 - [CVE-2026-24316] Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP
3719397
CVSS
6.1

Affected system type Java
Patchday 2026-04
Released on 2026/04/14
Description 3719397 - [CVE-2026-27674] Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
3645228
CVSS
6.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3645228 - [CVE-2026-0512] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3730639
CVSS
5.0

Affected system type HANA platform
Patchday 2026-04
Released on 2026/04/14
Description 3730639 - [CVE-2026-34262] Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
3703813
CVSS
4.9

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703813 - [CVE-2026-27673] Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
3711682
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3711682 - [CVE-2026-27676] Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures)
3703276
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3703276 - [CVE-2026-27672] Missing Authorization check in Material Master Application
3530544
CVSS
4.3

Affected system type ABAP
Patchday 2026-04
Released on 2025/11/11
Description 3530544 - [CVE-2025-42899] Missing Authorization check in SAP S4CORE (Manage Journal Entries)
3702191
CVSS
4.2

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3702191 - [CVE-2026-24318] Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
3698216
CVSS
4.1

Affected system type BI/BO platform
Patchday 2026-04
Released on 2026/04/14
Description 3698216 - [CVE-2026-27683] Reflected cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3665042
CVSS
3.1

Affected system type ABAP
Patchday 2026-04
Released on 2026/03/10
Description 3665042 - [CVE-2026-27680] CSS Injection vulnerability in SAP NetWeaver Application Server ABAP
3723097
CVSS
2.0

Affected system type ABAP
Patchday 2026-04
Released on 2026/04/14
Description 3723097 - [CVE-2026-27675] Code Injection vulnerability in SAP Landscape Transformation
3698553
CVSS
9.8

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3698553 - [CVE-2019-17571 ] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)
3714585
CVSS
9.1

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3714585 - [ CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
3697567
CVSS
8.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3697567 - [CVE-2026-23687] XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
3719502
CVSS
7.7

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3719502 - [CVE-2026-27689] Denial of service (DOS) in SAP Supply Chain Management
3695912
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-03
Released on 2026/02/10
Description 3695912 - [CVE-2026-24324] Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools)
3672622
CVSS
6.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/10
Description 3672622 - [CVE-2026-0484] Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
3703856
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703856 - [CVE-2026-24309] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3697355
CVSS
6.4

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3697355 - [CVE-2026-27684] SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)
3693543
CVSS
6.1

Affected system type SAP Business One
Patchday 2026-03
Released on 2026/03/10
Description 3693543 - [CVE-2026-0489] DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)
3703385
CVSS
5.9

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3703385 - [CVE-2026-27686] Missing Authorization check in SAP Business Warehouse (Service API)
3701020
CVSS
5.8

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3701020 - [CVE-2026-27687] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
3708457
CVSS
5.6

Affected system type SAP Customer Checkout
Patchday 2026-03
Released on 2026/03/10
Description 3708457 - [CVE-2026-24311] Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0
3704740
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3704740 - [CVE-2026-27688] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3707930
CVSS
5.0

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3707930 - [CVE-2026-24313] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3699761
CVSS
5.0

Affected system type SAP GUI / Frontend
Patchday 2026-03
Released on 2026/03/10
Description 3699761 - [CVE-2026-24317] DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT
3396109
CVSS
4.7

Affected system type ABAP
Patchday 2026-03
Released on 2024/02/13
Description 3396109 - [CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML
3646297
CVSS
4.3

Affected system type ABAP
Patchday 2026-03
Released on 2026/02/24
Description 3646297 - [CVE-2026-24314] Information Disclosure vulnerability in SAP S/4HANA (Manage Payment Media)
3700960
CVSS
4.3

Affected system type Java
Patchday 2026-03
Released on 2026/03/10
Description 3700960 - [Multiple CVEs] Denial of Service due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Services)
3694383
CVSS
3.5

Affected system type ABAP
Patchday 2026-03
Released on 2026/03/10
Description 3694383 - [CVE-2026-24310] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3697099
CVSS
9.9

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
3674774
CVSS
9.6

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3697979
CVSS
9.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/13
Description [CVE-2026-0491] Code Injection vulnerability in SAP Landscape Transformation
3697256
CVSS
7.7

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24325] Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console)
3703092
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23689] Denial of service (DOS) in SAP Supply Chain Management
3705882
CVSS
7.7

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24322] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
3654236
CVSS
7.5

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0490] Denial of service (DOS) in SAP BusinessObjects BI Platform
3692405
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2025-12383] Race Condition in SAP Commerce Cloud
3674246
CVSS
7.3

Affected system type BI/BO platform
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0508] Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform
3688319
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24328] Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
3678417
CVSS
6.1

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0505] Multiple vulnerabilities in BSP Applications of SAP Document Management System
3503138
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2026-02
Released on 2025/01/14
Description [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
3689543
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23684] Race condition vulnerability in SAP Commerce Cloud
3679346
CVSS
5.8

Affected system type SAP Business One
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24319] Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)
3687771
CVSS
5.3

Affected system type SAP Commerce Cloud
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24321] Information Disclosure vulnerability in SAP Commerce Cloud
3691645
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-0486] Missing Authorization Check in ABAP based SAP systems
3678009
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24326] Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)
3710111
CVSS
5.2

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24312] Missing authorization check in SAP Business Workflow
3687285
CVSS
4.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23685] Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
3215823
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23688] Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)
3122486
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/01/27
Description [CVE-2026-23683] Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation)
3680390
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24327] Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
3680416
CVSS
4.3

Affected system type ABAP
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23681] Missing Authorization check in a function module in SAP Support Tools Plug-In
3673213
CVSS
3.4

Affected system type Java
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-23686] CRLF Injection vulnerability in SAP NetWeaver Application Server Java
3678313
CVSS
3.1

Affected system type Kernel
Patchday 2026-02
Released on 2026/02/10
Description [CVE-2026-24320] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
3687749
CVSS
9.9

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0501] SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials – General Ledger)
3668679
CVSS
9.6

Affected system type SAP Solution Manager...
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0500] Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation)
3683579
CVSS
9.6

Affected system type SAP Commerce Cloud
Patchday 2026-01
Released on 2025/12/09
Description Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3685286
CVSS
9.1

Affected system type SAP Adaptive Server...
Patchday 2026-01
Released on 2025/12/09
Description [CVE-2025-42928] Deserialization Vulnerability in SAP jConnect - SDK for ASE
3694242
CVSS
9.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0498] Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise)
3691059
CVSS
8.8

Affected system type HANA platform
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0492] Privilege escalation vulnerability in SAP HANA database
3675151
CVSS
8.4

Affected system type Kernel
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0507] OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK
3688703
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0506] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3565506
CVSS
8.1

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0511] Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)
3681523
CVSS
6.4

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0503] Missing Authorization check in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)
3666061
CVSS
6.1

Affected system type SAP Business Connector
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0514] Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
3687372
CVSS
6.1

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0499] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3638716
CVSS
4.7

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0513] Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)
3677111
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0497] Missing Authorization check in Business Server Pages Application (Product Designer Web UI)
3655229
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0493] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3655227
CVSS
4.3

Affected system type ABAP
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0494] Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation)
3657998
CVSS
3.8

Affected system type SAP IDM
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0504] Insufficient Input Handling in JNDI Operations of SAP Identity Management
3593356
CVSS
3.0

Affected system type Java
Patchday 2026-01
Released on 2026/01/13
Description [CVE-2026-0510] Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping
3685270
CVSS
9.9

Affected system type ABAP
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42880] Code Injection vulnerability in SAP Solution Manager
3668705
CVSS
9.9

Affected system type ABAP
Patchday 2025-12
Released on 2025/11/11
Description [CVE-2025-42887] Code Injection vulnerability in SAP Solution Manager
3684682
CVSS
8.2

Affected system type Kernel / Web Dispatcher
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42878] Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
3640185
CVSS
7.9

Affected system type Java
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42874] Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
3677544
CVSS
7.5

Affected system type Kernel / Web Dispatcher
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42877] Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
3650226
CVSS
7.5

Affected system type BI/BO platform
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-48976] Denial of service (DOS) in SAP Business Objects
3672151
CVSS
7.1

Affected system type ABAP
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42876] Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)
3591163
CVSS
6.6

Affected system type ABAP
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42875] Missing Authentication check in SAP NetWeaver Internet Communication Framework
3662324
CVSS
6.5

Affected system type Kernel
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42904] Information Disclosure vulnerability in Application Server ABAP
3662622
CVSS
6.1

Affected system type Java
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42872] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3676970
CVSS
5.9

Affected system type SAP UI5
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42873] Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)
3659117
CVSS
5.5

Affected system type ABAP
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42891] Missing Authorization check in SAP Enterprise Search for ABAP
3651390
CVSS
5.4

Affected system type BI/BO platform
Patchday 2025-12
Released on 2025/12/09
Description [CVE-2025-42896] Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform
3610322
CVSS
4.9

Affected system type ABAP
Patchday 2025-12
Released on 2025/07/08
Description [CVE-2025-42961] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3626440
CVSS
4.3

Affected system type ABAP
Patchday 2025-12
Released on 2025/07/08
Description [CVE-2025-42986] Missing Authorization check in SAP NetWeaver and ABAP Platform
3666261
CVSS
10.0

Affected system type Sybase platform
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42890] Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
3660659
CVSS
10.0

Affected system type Java
Patchday 2025-11
Released on 2025/10/14
Description [CVE-2025-42944] Security Hardening for Insecure Deserialization in SAP NetWeaver AS Java
3647332
CVSS
9.0

Affected system type ABAP
Patchday 2025-11
Released on 2025/10/14
Description [CVE-2025-42910] Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management
3633049
CVSS
7.5

Affected system type SAP Cryptolib
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42940] Memory Corruption vulnerability in SAP CommonCryptoLib
3664466
CVSS
7.5

Affected system type SAP Commerce Cloud
Patchday 2025-11
Released on 2025/10/14
Description [CVE-2025-5115] Denial of service (DOS) in SAP Commerce Cloud (Search and Navigation)
3643385
CVSS
6.9

Affected system type SAP HANA Client
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42895 ] Code Injection vulnerability in SAP HANA JDBC Client
3665900
CVSS
6.8

Affected system type SAP Business Connector
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42892] OS Command Injection vulnerability in SAP Business Connector
3666038
CVSS
6.8

Affected system type SAP Business Connector
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42894] Path Traversal vulnerability in SAP Business Connector
3660969
CVSS
6.5

Affected system type Java
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42884] JNDI Injection vulnerability in SAP NetWeaver Enterprise Portal
3662000
CVSS
6.1

Affected system type SAP Business Connector
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42893] Open Redirect vulnerability in SAP Business Connector
3597355
CVSS
6.1

Affected system type ABAP
Patchday 2025-11
Released on 2025/08/12
Description [CVE-2025-42942] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP
3665907
CVSS
6.1

Affected system type SAP Business Connector
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42886] Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
3642398
CVSS
6.1

Affected system type ABAP
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42924] Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP)
3639264
CVSS
5.8

Affected system type SAP HANA Platform
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42885] Missing authentication in SAP HANA 2.0 (hdbrss)
3651097
CVSS
5.5

Affected system type SAP GUI / Frontend
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42888] Information Disclosure vulnerability in SAP GUI for Windows
2886616
CVSS
5.4

Affected system type ABAP
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42889] SQL Injection vulnerability in SAP Starter Solution (PL SAFT)
3652901
CVSS
5.3

Affected system type SAP Business One
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42897] Information Disclosure vulnerability in SAP Business One (SLD)
3643603
CVSS
5.3

Affected system type Java
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42919] Information Disclosure vulnerability in SAP NetWeaver Application Server Java
3627644
CVSS
5.0

Affected system type ABAP
Patchday 2025-11
Released on 2025/09/09
Description [CVE-2025-42911] Missing Authorization check in SAP NetWeaver (Service Data Download)
3643337
CVSS
4.3

Affected system type ABAP
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42882] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3617142
CVSS
3.5

Affected system type BI/BO platform
Patchday 2025-11
Released on 2025/10/14
Description [CVE-2025-31672] Deserialization Vulnerability in SAP BusinessObjects (Web Intelligence and Platform Search)
3426825
CVSS
3.1

Affected system type ABAP
Patchday 2025-11
Released on 2025/02/11
Description [CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP
3634053
CVSS
2.7

Affected system type ABAP
Patchday 2025-11
Released on 2025/11/11
Description [CVE-2025-42883] Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)
3634501
CVSS
10.0

Affected system type Java
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42944] Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
3643865
CVSS
9.9

Affected system type Java
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42922] Insecure File Operations vulnerability in SAP NetWeaver AS Java (Deploy Web Service)
3630595
CVSS
9.8

Affected system type SAPSprint
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42937] Directory Traversal vulnerability in SAP Print Service
3302162
CVSS
9.6

Affected system type ABAP
Patchday 2025-10
Released on 2023/03/14
Description [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3658838
CVSS
7.1

Affected system type SAP Data Hub
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-48913]Security Misconfiguration vulnerability in SAP Data Hub Integration Suite
3635587
CVSS
6.5

Affected system type ABAP
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42912] Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)
3643832
CVSS
6.5

Affected system type ABAP
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42917] Missing Authorization check in SAP HCM (Approve Timesheets Fiori 2.0 application)
3441087
CVSS
5.4

Affected system type ABAP
Patchday 2025-10
Released on 2025/06/10
Description [CVE-2025-42984] Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application)
3642021
CVSS
5.4

Affected system type Kernel
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42908] Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP
3409013
CVSS
5.4

Affected system type ABAP
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42915] Missing Authorization Check in Fiori app (Manage Payment Blocks)
3652788
CVSS
5.4

Affected system type ABAP
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42901] Code Injection vulnerability in SAP Application Server for ABAP (BAPI Browser)
3627308
CVSS
5.3

Affected system type Kernel
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42902] Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform
3634724
CVSS
5.3

Affected system type SAP Commerce Cloud
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42906] Directory Traversal vulnerability in SAP Commerce Cloud
3625683
CVSS
4.3

Affected system type ABAP
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42939] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)
3623504
CVSS
4.3

Affected system type ABAP
Patchday 2025-10
Released on 2025/09/09
Description [CVE-2025-42918] Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)
3577131
CVSS
4.3

Affected system type ABAP
Patchday 2025-10
Released on 2025/04/08
Description [CVE-2025-31331] Authorization Bypass vulnerability in SAP NetWeaver
3656781
CVSS
4.3

Affected system type ABAP
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42903] User Enumeration and Sensitive Data Exposure via RFC Function in SAP Financial Service Claims Management
3540622
CVSS
4.3

Affected system type BI/BO platform
Patchday 2025-10
Released on 2025/09/23
Description [CVE-2025-42907] Server-Side Request Forgery in SAP BI Platform
3643871
CVSS
3.0

Affected system type ABAP
Patchday 2025-10
Released on 2025/10/14
Description [CVE-2025-42909] Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances
3627373
CVSS
9.1

Affected system type Kernel
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42958] Missing Authentication check in SAP NetWeaver
3642961
CVSS
8.8

Affected system type SAP Business One
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42933] Insecure Storage of Sensitive Information in SAP Business One (SLD)
3635475
CVSS
8.1

Affected system type ABAP
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42916] Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
3633002
CVSS
8.1

Affected system type ABAP
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42929] Missing input validation vulnerability in SAP Landscape Transformation Replication Server
3581811
CVSS
7.7

Affected system type ABAP
Patchday 2025-09
Released on 2025/04/08
Description [CVE-2025-27428] Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection)
3620264
CVSS
6.6

Affected system type SAP Commerce Cloud SAP DataHub
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-22228] Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP Datahub
3614067
CVSS
6.5

Affected system type ABAP
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42930] Denial of Service (DoS) vulnerability in SAP Business Planning and Consolidation
3611420
CVSS
6.5

Affected system type BI/BO platform
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2023-5072] Denial of Service (DoS) vulnerability due to outdated JSON library used in SAP BusinessObjects Business Intelligence Platform
3629325
CVSS
6.1

Affected system type ABAP
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42938] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform
3647098
CVSS
6.1

Affected system type ABAP
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42920] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management
3619465
CVSS
5.3

Affected system type Java
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42926] Missing Authentication check in SAP NetWeaver Application Server Java
3450692
CVSS
4.3

Affected system type SAP Fiori
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42923] Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (F4044 Manage Work Center Groups)
3640477
CVSS
4.3

Affected system type Java
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42925] Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
3624943
CVSS
3.5

Affected system type SAP UI5
Patchday 2025-09
Released on 2025/08/12
Description [CVE-2025-42941] Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
3525295
CVSS
3.4

Affected system type Java
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2025-42927] Information Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)
3632154
CVSS
3.1

Affected system type SAP Commerce Cloud
Patchday 2025-09
Released on 2025/09/09
Description [CVE-2024-13009] Potential Improper Resource Release vulnerability in SAP Commerce Cloud
3627998
CVSS
9.9

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42957] Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
3633838
CVSS
9.9

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42950] Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)
3581961
CVSS
9.9

Affected system type ABAP
Patchday 2025-08
Released on 2025/04/08
Description [CVE-2025-27429] Code Injection Vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
3610892
CVSS
9.1

Affected system type Java
Patchday 2025-08
Released on 2025/07/08
Description [CVE-2025-42966] Insecure Deserialization vulnerability in SAP NetWeaver (XML Data Archiving Service)
3625403
CVSS
8.8

Affected system type SAP Business One
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42951] Broken Authorization in SAP Business One (SLD)
3611184
CVSS
8.1

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42976] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP (BIC Document)
3600846
CVSS
8.1

Affected system type ABAP
Patchday 2025-08
Released on 2025/07/08
Description [CVE-2025-42959] Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
3614804
CVSS
6.9

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42946] Directory Traversal vulnerability in SAP S/4HANA (Bank Communication Management)
3585491
CVSS
6.1

Affected system type Kernel
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42945] HTML Injection vulnerability in SAP NetWeaver Application Server ABAP
3596987
CVSS
6.1

Affected system type ABAP
Patchday 2025-08
Released on 2025/07/08
Description [CVE-2025-42969] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3617131
CVSS
6.1

Affected system type ABAP
Patchday 2025-08
Released on 2025/07/08
Description [CVE-2025-42981] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
3629871
CVSS
6.1

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42948] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform
3585992
CVSS
5.8

Affected system type ABAP
Patchday 2025-08
Released on 2025/05/13
Description [CVE-2025-43008] Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal
3602656
CVSS
5.4

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42936] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3561792
CVSS
5.3

Affected system type Java
Patchday 2025-08
Released on 2025/03/11
Description [CVE-2025-23194] Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)
3626722
CVSS
4.9

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42949] Missing Authorization check in ABAP Platform
3627845
CVSS
4.5

Affected system type SAP GUI / Frontend
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42943] Information Disclosure in SAP GUI for Windows
3616863
CVSS
4.3

Affected system type ABAP
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42934] CRLF Injection vulnerability in SAP S/4HANA (Supplier invoice)
3601480
CVSS
4.1

Affected system type Kernel
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42935] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager)
3611345
CVSS
3.5

Affected system type SAP Cloud Connector
Patchday 2025-08
Released on 2025/08/12
Description [CVE-2025-42955] Missing authorization check in SAP Cloud Connector
3557179
CVSS
3.5

Affected system type Java
Patchday 2025-08
Released on 2025/07/08
Description [CVE-2025-42978] Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server Java
3578900
CVSS
10.0

Affected system type Java
Patchday 2025-07
Released on 2025/05/13
Description [CVE-2025-30012] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)
3618955
CVSS
9.9

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42967] Code Injection vulnerability in SAP S/4HANA and SAP SCM (Characteristic Propagation)
3621236
CVSS
9.1

Affected system type Java
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42964] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration
3621771
CVSS
9.1

Affected system type Java
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42963] Insecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer )
3620498
CVSS
9.1

Affected system type Java
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42980] Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network
3623440
CVSS
8.1

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42953] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3565279
CVSS
8.0

Affected system type BI/BO platform
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2024-53677] Insecure File Operations vulnerability in SAP Business Objects Business Intelligence Platform (CMC)
3623255
CVSS
7.7

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42952] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
3610591
CVSS
7.6

Affected system type ABAP
Patchday 2025-07
Released on 2025/06/10
Description [CVE-2025-42977] Directory Traversal vulnerability in SAP NetWeaver Visual Composer
3595143
CVSS
6.9

Affected system type SAPCAR
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-43001] Multiple Privilege Escalation Vulnerabilities in SAPCAR
3580384
CVSS
6.7

Affected system type ABAP
Patchday 2025-07
Released on 2025/06/10
Description [CVE-2025-42993] Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement)
3604212
CVSS
6.1

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42962] Cross-Site Scripting (XSS) vulnerability in SAP Business Warehouse (Business Explorer Web 3.5 loading animation)
3617380
CVSS
6.1

Affected system type BI/BO platform
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42985] Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench
3595156
CVSS
5.8

Affected system type SAPCAR
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42970] Directory Traversal vulnerability in SAPCAR
3607513
CVSS
5.6

Affected system type SAP GUI / Frontend
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42979] Insecure Key & Secret Management vulnerability in SAP GUI for Windows
3606103
CVSS
5.4

Affected system type SAP Data Services
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42973] Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report)
3621037
CVSS
5.0

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42968] Missing Authorization check in SAP NetWeaver (RFC enabled function module)
3608991
CVSS
4.3

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42960] Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA BEx Tools
3610056
CVSS
4.3

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42974] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)
3598118
CVSS
4.1

Affected system type BI/BO platform
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42965] Server Side Request Forgery(SSRF) vulnerability in SAP BusinessObjects BI Platform Central Management Console Promotion Management Application.
3573199
CVSS
4.1

Affected system type BI/BO platform
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-31326] HTML Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3595141
CVSS
4.0

Affected system type SAPCAR
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42971] Memory Corruption vulnerability in SAPCAR
3608156
CVSS
2.7

Affected system type ABAP
Patchday 2025-07
Released on 2025/07/08
Description [CVE-2025-42954] Denial of service (DOS) in SAP NetWeaver Business Warehouse (CCAW application).
3600840
CVSS
9.6

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42989] Missing Authorization check in SAP NetWeaver Application Server for ABAP
3604119
CVSS
9.1

Affected system type Java
Patchday 2025-06
Released on 2025/05/13
Description [CVE-2025-42999] Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
3609271
CVSS
8.8

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42982] Information Disclosure in SAP GRC (AC Plugin)
3474398
CVSS
8.7

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/01/14
Description [CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3606484
CVSS
8.5

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42983] Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
3560693
CVSS
8.2

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-23192] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (BI Workspace)
3591978
CVSS
7.7

Affected system type ABAP
Patchday 2025-06
Released on 2025/05/13
Description [CVE-2025-43011] Missing Authorization Check in SAP Landscape Transformation (PCL Basis)
3610006
CVSS
7.5

Affected system type SAP MDM Server
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42994] Multiple vulnerabilities in SAP MDM Server
3590887
CVSS
5.8

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-31325] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation)
3594258
CVSS
5.3

Affected system type SAP Business One
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42998] Security misconfiguration vulnerability in SAP Business One Integration Framework
3608058
CVSS
4.3

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42991] Missing Authorization check in SAP S/4HANA (Bank Account Application)
3596850
CVSS
4.3

Affected system type ABAP
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42987] Missing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statement)
3585545
CVSS
3.7

Affected system type BI/BO platform
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42988] Server-Side Request Forgery in SAP Business Objects Business Intelligence Platform
3601169
CVSS
3.0

Affected system type SAP UI5
Patchday 2025-06
Released on 2025/06/10
Description [CVE-2025-42990] HTML Injection in Unprotected SAPUI5 applications
3594142
CVSS
10.0

Affected system type Java
Exploit available
Patchday 2025-05
Released on 2025/04/24
Description [CVE-2025-31324] Missing Authorization check in SAP NetWeaver (Visual Composer development server)
3587115
CVSS
9.9

Affected system type ABAP
Patchday 2025-05
Released on 2025/04/08
Description [CVE-2025-31330] Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)
3600859
CVSS
8.3

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43010] Code injection vulnerability in SAP S/4HANA Cloud Private Edition or On Premise(SCM Master Data Layer (MDL))
3586013
CVSS
7.9

Affected system type BI/BO platform
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43000] Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW)
3483344
CVSS
7.7

Affected system type ABAP
Patchday 2025-05
Released on 2024/07/09
Description [CVE-2024-39592] Missing Authorization check in SAP PDCE
3577300
CVSS
6.6

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-42997] Information Disclosure vulnerability in SAP Gateway Client
3596033
CVSS
6.4

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43003] Information Disclosure vulnerability in SAP S/4HANA (Private Cloud & On-Premise)
2719724
CVSS
6.3

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43007] Missing Authorization check in SAP Service Parts Management (SPM)
2491817
CVSS
6.3

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43009] Missing Authorization check in SAP Service Parts Management (SPM)
3577287
CVSS
6.2

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-31329] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3588455
CVSS
6.1

Affected system type Java
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43006] Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)
3571096
CVSS
5.3

Affected system type SAP Digital...
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43004] Security Misconfiguration Vulnerability in SAP Digital Manufacturing (Production Operator Dashboard)
3446649
CVSS
4.6

Affected system type ABAP
Patchday 2025-05
Released on 2025/04/22
Description [CVE-2025-31328] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution)
3558755
CVSS
4.4

Affected system type SAP Data Services
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-26662] Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console
3574520
CVSS
4.3

Affected system type SAP GUI / Frontend
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43005] Information Disclosure vulnerability in SAP GUI for Windows
3359825
CVSS
4.3

Affected system type ABAP
Patchday 2025-05
Released on 2025/04/22
Description [CVE-2025-31327] OData meta-data property entity tampering in SAP Field Logistics
3227940
CVSS
4.3

Affected system type ABAP
Patchday 2025-05
Released on 2025/05/13
Description [CVE-2025-43002] Missing Authorization check in SAP S4/HANA (OData meta-data property)
3572688
CVSS
9.8

Affected system type SAP Financial Consolidation
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-30016] Authentication Bypass Vulnerability in SAP Financial Consolidation
3525794
CVSS
8.8

Affected system type BI/BO platform
Patchday 2025-04
Released on 2025/02/11
Description [CVE-2025-0064] Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)
3554667
CVSS
8.5

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-23186] Mixed Dynamic RFC Destination vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
3590984
CVSS
8.1

Affected system type SAP Commerce Cloud
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2024-56337] Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat within SAP Commerce Cloud
2927164
CVSS
7.7

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-30014] Directory Traversal vulnerability in SAP Capital Yield Tax Management
3543274
CVSS
6.8

Affected system type SAP Commerce Cloud
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-26654] Potential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)
3571093
CVSS
6.7

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-30013] Code Injection vulnerability in SAP ERP BW Business Content
3565751
CVSS
6.6

Affected system type BI/BO platform
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-31332] Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform
3568307
CVSS
5.3

Affected system type Java
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-26657] Information Disclosure vulnerability in SAP KMC WPC
3559307
CVSS
4.7

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-26653] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
3558864
CVSS
4.4

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-30017] Missing Authorization check in SAP Solution Manager
3525971
CVSS
4.3

Affected system type ABAP
Patchday 2025-04
Released on 2024/10/10
Description [CVE-2025-31333] Odata meta-data tampering in SAP S4CORE entity
3568778
CVSS
4.3

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-27437] Missing Authorization check in SAP NetWeaver Application Server ABAP (Virus Scan Interface)
3539465
CVSS
4.2

Affected system type SAP Commerce Cloud
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-27435] Information Disclosure Vulnerability in SAP Commerce Cloud
3565944
CVSS
4.1

Affected system type ABAP
Patchday 2025-04
Released on 2025/04/08
Description [CVE-2025-30015] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
3561861
CVSS
3.5

Affected system type ABAP
Patchday 2025-04
Released on 2025/03/11
Description [CVE-2025-27430] Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)
3569602
CVSS
8.8

Affected system type SAP Commerce
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-27434] Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI)
3563927
CVSS
8.8

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-26661] Missing Authorization check in SAP NetWeaver (ABAP Class Builder)
3566851
CVSS
8.6

Affected system type SAP Commerce Cloud
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2024-38286] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3567974
CVSS
8.1

Affected system type SAP Approuter
Patchday 2025-03
Released on 2025/02/11
Description [CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter
3561045
CVSS
6.8

Affected system type SAP Business One
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-26658] Broken Authentication in SAP Business One (Service Layer)
3562390
CVSS
6.1

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-25242] Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP
3552824
CVSS
6.1

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-26659] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
3552144
CVSS
5.7

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-25244] Missing Authorization Check in SAP Business Warehouse (Process Chains)
3567246
CVSS
5.4

Affected system type Java
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-27431] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java
3557469
CVSS
5.4

Affected system type BI/BO platform
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-25245] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3558132
CVSS
4.9

Affected system type Kernel
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-0071] Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager
3557459
CVSS
4.7

Affected system type BI/BO platform
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-0062] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3557131
CVSS
4.3

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-23188] Missing Authorization check in SAP S/4HANA (RBD)
3557655
CVSS
4.3

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-26660] Broken Access Control in SAP Fiori apps (Posting Library)
3475427
CVSS
4.3

Affected system type SAP Fiori
Patchday 2025-03
Released on 2024/08/13
Description [CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work
3565835
CVSS
4.3

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-27433] Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)
3474392
CVSS
4.3

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-26656] Missing Authorization check in S/4HANA (Manage Purchasing Info Records)
3549494
CVSS
4.1

Affected system type BI/BO platform
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-23185] Information Disclosure in SAP Business Objects Business Intelligence Platform
3562415
CVSS
3.7

Affected system type SAP Commerce Cloud SAP DataHub
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2024-38819] Multiple vulnerabilities in Spring Framework within SAP Commerce Cloud and SAP Datahub
3347991
CVSS
3.1

Affected system type ABAP
Patchday 2025-03
Released on 2025/02/24
Description [CVE-2025-26655] Missing Authorization check in SAP JIT(Outbound)
3568865
CVSS
2.4

Affected system type ABAP
Patchday 2025-03
Released on 2025/03/11
Description [CVE-2025-27432] Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit)
3576540
CVSS
0.0

Affected system type BTP
Patchday 2025-03
Released on 2025/03/11
Description Open Source Security Advisory: Best Practices for Securing Spring Boot Actuator Endpoints for applications running on BTP
3417627
CVSS
8.8

Affected system type Java
Patchday 2025-02
Released on 2024/02/13
Description [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
3567551
CVSS
8.6

Affected system type Java
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-25243] Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)
3567172
CVSS
7.5

Affected system type SAP Enterprise...
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2024-38819] Multiple vulnerabilities in SAP Enterprise Project Connection
3563929
CVSS
7.1

Affected system type SAP HANA Platform
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24868] Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services)
3559510
CVSS
6.8

Affected system type SAP Commerce Cloud
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24874] Missing Defense in Depth Against Clickjacking in SAP Commerce (Backoffice)
3555364
CVSS
6.8

Affected system type SAP Commerce Cloud
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24875] SameSite Defense in Depth not applied for some cookies in SAP Commerce
3445708
CVSS
6.1

Affected system type BI/BO platform
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24867] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad)
3557138
CVSS
6.1

Affected system type Java
Patchday 2025-02
Released on 2025/02/11
Description Update 1 to Security Note 3417627 - [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application)
3562336
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24870] Insecure Key & Secret Management vulnerability in SAP GUI for Windows
3540273
CVSS
5.5

Affected system type SAP Commerce Cloud
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2024-45216] Multiple vulnerabilities in Apache Solr within SAP Commerce Cloud
3526203
CVSS
5.4

Affected system type Java
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-0054] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java
3532025
CVSS
5.4

Affected system type ABAP
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-25241] Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests)
3287784
CVSS
5.3

Affected system type Java
Patchday 2025-02
Released on 2023/04/11
Description [CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service
3546470
CVSS
5.3

Affected system type ABAP
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-23187] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)
3561264
CVSS
5.3

Affected system type ABAP
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-23193] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP
3550027
CVSS
4.3

Affected system type Java
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24869] Information Disclosure vulnerability in SAP NetWeaver Application Server Java
3553753
CVSS
4.3

Affected system type ABAP
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-24872] Missing Authorization check in SAP ABAP Platform (ABAP Build Framework)
3547581
CVSS
4.3

Affected system type ABAP
Patchday 2025-02
Released on 2025/02/11
Description [CVE-2025-23190] Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI)
3550708
CVSS
9.9

Affected system type ABAP
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0066] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Framework)
3537476
CVSS
9.9

Affected system type Kernel
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0070] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
3550816
CVSS
8.8

Affected system type ABAP
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0063] SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3542533
CVSS
7.8

Affected system type SAPSetup
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0069] DLL Hijacking vulnerability in SAPSetup
3542698
CVSS
6.5

Affected system type ABAP
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0058] Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow
3540108
CVSS
6.3

Affected system type Java
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0067] Missing Authorization check in SAP NetWeaver Application Server Java
3472837
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0055] Information Disclosure vulnerability in SAP GUI for Windows
3502459
CVSS
6.0

Affected system type SAP GUI / Frontend
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0056] Information Disclosure vulnerability in SAP GUI for Java
3536461
CVSS
5.3

Affected system type ABAP
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0053] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3514421
CVSS
4.8

Affected system type Java
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0057] Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)
3550674
CVSS
4.3

Affected system type ABAP
Patchday 2025-01
Released on 2025/01/14
Description [CVE-2025-0068] Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
3492169
CVSS
2.2

Affected system type BI/BO platform
Patchday 2025-01
Released on 2025/01/14
Description Multiple Buffer overflow vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise)
3536965
CVSS
9.1

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47578] Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
3520281
CVSS
8.8

Affected system type SAP Web Dispatcher
Patchday 2024-12
Released on 2024/11/12
Description [CVE-2024-47590] Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher
3469791
CVSS
8.5

Affected system type ABAP
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-54198] Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
3504390
CVSS
7.5

Affected system type ABAP
Patchday 2024-12
Released on 2024/11/12
Description [CVE-2024-47586] NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3542543
CVSS
7.2

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-54197] Server-Side Request Forgery in SAP NetWeaver Administrator (System Overview)
3524933
CVSS
5.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-32732] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
3351041
CVSS
5.3

Affected system type Java
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47582] XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA
3536361
CVSS
4.3

Affected system type ABAP
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47585] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3433545
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/08/13
Description [CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3515653
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-12
Released on 2024/12/10
Description Update 1 to Security Note 3433545: [CVE-2024-42375] Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform
3522332
CVSS
4.2

Affected system type ABAP
Patchday 2024-12
Released on 2024/11/26
Description [CVE-2024-47581] Missing Authorization check in SAP HCM (Approve Timesheets version 4)
3504847
CVSS
3.3

Affected system type SAP Product Lifecycle Costing
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47576] DLL Hijacking vulnerability in SAP Product Lifecycle Costing
3535451
CVSS
2.7

Affected system type SAP Commerce Cloud
Patchday 2024-12
Released on 2024/12/10
Description [CVE-2024-47577] Information Disclosure vulnerability in SAP Commerce Cloud
3335394
CVSS
6.5

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-42372] Missing Authorization check in SAP NetWeaver AS Java (System Landscape Directory)
3509619
CVSS
6.3

Affected system type SAP Host Agent
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47595] Local Privilege Escalation in SAP Host Agent
3393899
CVSS
5.3

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47592] Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)
3522953
CVSS
4.7

Affected system type Java
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47588] Information Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)
3508947
CVSS
4.3

Affected system type ABAP
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47593] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3392049
CVSS
3.5

Affected system type ABAP
Patchday 2024-11
Released on 2024/05/14
Description [CVE-2024-33000] Missing Authorization check in SAP Bank Account Management
3498470
CVSS
3.5

Affected system type ABAP
Patchday 2024-11
Released on 2024/11/12
Description [CVE-2024-47587] Missing authorization check in SAP Cash Management (Cash Operations)
3479478
CVSS
9.8

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-41730] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
3523541
CVSS
8.0

Affected system type SAP Enterprise...
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2022-23302] Multiple vulnerabilities in SAP Enterprise Project Connection
3478615
CVSS
7.7

Affected system type BI/BO platform
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-37179] Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)
3495876
CVSS
6.5

Affected system type Sybase platform
Patchday 2024-10
Released on 2024/08/13
Description [Multiple CVEs] Multiple vulnerabilities in SAP Replication Server (FOSS)
3477359
CVSS
6.0

Affected system type Java
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-45283] Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)
3503462
CVSS
5.4

Affected system type Java
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3507545
CVSS
5.4

Affected system type SAP Commerce
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45278] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
3479293
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/08/13
Description [CVE-2024-42373] Missing Authorization Check in SAP Student Life Cycle Management (SLcM)
3251893
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/24
Description [CVE-2024-45282] HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)
3520100
CVSS
4.3

Affected system type SAP HANA Client
Patchday 2024-10
Released on 2024/10/08
Description [CVE-2024-45277] Prototype Pollution vulnerability in SAP HANA Client
3481588
CVSS
4.3

Affected system type ABAP
Patchday 2024-10
Released on 2024/09/10
Description [CVE-2024-41729] Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)
3454858
CVSS
4.1

Affected system type ABAP
Patchday 2024-10
Released on 2024/07/09
Description [CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3459935
CVSS
7.4

Affected system type SAP Commerce Cloud
Patchday 2024-09
Released on 2024/08/13
Description [CVE-2024-33003] Information Disclosure Vulnerability in SAP Commerce Cloud
3488341
CVSS
6.5

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45286] Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface)
3501359
CVSS
6.1

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45279] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP(CRM Blueprint Application Builder Panel)
3497347
CVSS
6.1

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-42378] Cross-Site Scripting (XSS) in eProcurement on S/4HANA
3430336
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2013-3587] Information Disclosure vulnerability in SAP Commerce Cloud
3425287
CVSS
5.8

Affected system type BI/BO platform
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45281] DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform
3488039
CVSS
5.4

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
3505503
CVSS
4.8

Affected system type Java
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45280] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)
3498221
CVSS
4.7

Affected system type Java
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44120] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3437585
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/08/27
Description [CVE-2024-44121] Information Disclosure in SAP S/4 HANA (Statutory Reports)
3481992
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44113] Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
3505293
CVSS
4.3

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44112] Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution)
2256627
CVSS
2.7

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-45284] Missing authorization check in SAP Student Life Cycle Management (SLcM)
3496410
CVSS
2.7

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-41728] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3507252
CVSS
2.0

Affected system type ABAP
Patchday 2024-09
Released on 2024/09/10
Description [CVE-2024-44114] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3477196
CVSS
9.1

Affected system type SAP Build Apps
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-29415] Server-Side Request Forgery vulnerability in applications built with SAP Build Apps
3485284
CVSS
8.2

Affected system type Java
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-42374] XML injection in SAP BEx Web Java Runtime Export Web Service
3423268
CVSS
7.8

Affected system type SAP Fiori
Patchday 2024-08
Released on 2024/07/23
Description [CVE-2023-30533] Prototype Pollution in SAP S/4 HANA (Manage Supply Protection)
3474590
CVSS
6.5

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-42376] Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework
3438085
CVSS
6.3

Affected system type Kernel / Web Dispatcher
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-33005] Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server.
3483256
CVSS
5.4

Affected system type SAP Commerce
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41735] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice
3471450
CVSS
5.3

Affected system type SAP Commerce
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41733] Information Disclosure Vulnerability in SAP Commerce
3487537
CVSS
5.0

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41737] Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
3468102
CVSS
4.7

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41732] Improper Access Control in SAP Netweaver Application Server ABAP
3494349
CVSS
4.3

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-41734] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
3477423
CVSS
4.3

Affected system type ABAP
Patchday 2024-08
Released on 2024/08/13
Description [CVE-2024-39591] Missing Authorization check in SAP Document Builder
3490515
CVSS
7.2

Affected system type SAP Commerce
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce
3466801
CVSS
6.9

Affected system type SAP Landscape Management
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
3467377
CVSS
6.1

Affected system type SAP CRM UI
Patchday 2024-07
Released on 2024/07/09
Description [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
3482217
CVSS
6.1

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
3468681
CVSS
6.1

Affected system type Java
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34685] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLEditor
3457354
CVSS
5.4

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
3469958
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal)
3458789
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
3485805
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Allowlisting of callback-URLs in SAP Business Workflow (WebFlow Services)
3483993
CVSS
5.0

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34689] Prerequisite for Security Note 3458789
3461110
CVSS
5.0

Affected system type SAP GUI / Frontend
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows
3456952
CVSS
4.7

Affected system type ABAP
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
3476348
CVSS
4.3

Affected system type SAP Enable Now
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now
3476340
CVSS
3.3

Affected system type SAP Enable Now
Patchday 2024-07
Released on 2024/07/09
Description [CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now
3457592
CVSS
8.1

Affected system type SAP Financial Consolidation
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-37177] Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
3460407
CVSS
7.5

Affected system type Java
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)
3459379
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34683] Unrestricted file upload in SAP Document Builder (HTTP service)
3453170
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-33001] Denial of service (DOS) in SAP NetWeaver and ABAP platform
3466175
CVSS
6.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34691] Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
3465129
CVSS
6.1

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34686] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3465455
CVSS
5.5

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-37176] Missing Authorization check in SAP BW/4HANA Transformation and DTP
3457265
CVSS
5.4

Affected system type ABAP
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34690] Missing Authorization check in SAP Student Life Cycle Management (SLcM)
3425571
CVSS
5.3

Affected system type Java
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-28164] Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)
3441817
CVSS
3.7

Affected system type BI/BO platform
Patchday 2024-06
Released on 2024/06/11
Description [CVE-2024-34684] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Scheduling)
3455438
CVSS
9.8

Affected system type SAP Commerce Cloud
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2019-17495] Multiple vulnerabilities in SAP CX Commerce
3448171
CVSS
9.6

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33006] File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3431794
CVSS
8.1

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-28165] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3448445
CVSS
6.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-34687] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
3460772
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33002] Cross-Site Scripting (XSS) Vulnerability in SAP S/4HANA (Document Service Handler for DPS)
3450286
CVSS
6.1

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32733] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3447467
CVSS
5.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-32731] Missing Authorization check in SAP My Travel Requests
3349468
CVSS
4.9

Affected system type Sybase platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
3449093
CVSS
4.3

Affected system type BI/BO platform
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33004] Insecure Storage vulnerability in SAP BusinessObjects Business Intelligence Platform (Webservices)
3434666
CVSS
4.3

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [Multiple CVEs] Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)
1938764
CVSS
4.2

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33009] SQL injection vulnerability in SAP Global Label Management (GLM)
3446076
CVSS
3.5

Affected system type ABAP
Patchday 2024-05
Released on 2024/05/14
Description [CVE-2024-33007] Client-side script execution vulnerability in SAP UI5(PDFViewer)
3434839
CVSS
8.8

Affected system type Java
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27899] Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
3421384
CVSS
7.7

Affected system type BI/BO platform
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-25646] Information Disclosure vulnerability in SAP BusinessObjects Web Intelligence
3438234
CVSS
7.2

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27901] Directory Traversal vulnerability in SAP Asset Accounting
3442741
CVSS
6.8

Affected system type SAP Edge Integration
Patchday 2024-04
Released on 2024/04/09
Description Stack overflow vulnerability on the component images of SAP Integration Suite (EDGE INTEGRATION CELL)
3442378
CVSS
6.5

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-28167] Missing Authorization check in SAP Group Reporting Data Collection (Enter Package Data)
3359778
CVSS
6.5

Affected system type Kernel
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30218] Denial of service (DOS) vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
3425188
CVSS
5.3

Affected system type Java
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-27898] Server-Side Request Forgery in SAP NetWeaver (tc~esi~esp~grmg~wshealthcheck~ear)
3421453
CVSS
4.8

Affected system type SAP Business Connector
Patchday 2024-04
Released on 2024/04/09
Description [Multiple CVEs] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Connector
3430173
CVSS
4.3

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30217] Missing Authorization check in SAP S/4 HANA (Cash Management)
3427178
CVSS
4.3

Affected system type ABAP
Patchday 2024-04
Released on 2024/04/09
Description [CVE-2024-30216] Missing Authorization check in SAP S/4 HANA (Cash Management)
3425274
CVSS
9.4

Affected system type SAP Build Apps
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2019-10744] Code Injection vulnerability in applications built with SAP Build Apps
3433192
CVSS
9.1

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-22127] Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
3410615
CVSS
7.5

Affected system type HANA platform
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2023-44487 ] Denial of service (DOS) in SAP HANA XS Classic and HANA XS Advanced
3414195
CVSS
7.2

Affected system type BI/BO platform
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2023-50164] Path Traversal Vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
3377979
CVSS
5.4

Affected system type Kernel
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-27902] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP, applications based on SAPGUI for HTML (WebGUI)
3428847
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-25645] Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
3434192
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-28163] Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pages)
3425682
CVSS
5.3

Affected system type Java
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-25644] Information Disclosure vulnerability in SAP NetWeaver (WSRM)
3417399
CVSS
4.6

Affected system type ABAP
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-22133] Improper Access Control in SAP Fiori Front End Server
3419022
CVSS
4.3

Affected system type ABAP
Patchday 2024-03
Released on 2024/03/12
Description [CVE-2024-27900]Missing Authorization check in SAP ABAP Platform
3420923
CVSS
9.1

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22131] Code Injection vulnerability in SAP ABA (Application Basis)
3426111
CVSS
8.6

Affected system type Java
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
3410875
CVSS
7.6

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22130] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3424610
CVSS
7.4

Affected system type SAP Cloud Connector
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-25642] Improper Certificate Validation in SAP Cloud Connector
3421659
CVSS
7.4

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22132] Code Injection vulnerability in SAP IDES Systems
2637727
CVSS
6.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24739] Missing authorization check in SAP Bank Account Management
3404025
CVSS
5.4

Affected system type SAP Enable Now
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-22129] Cross-Site Scripting (XSS) vulnerability in SAP Companion
3360827
CVSS
5.3

Affected system type Kernel
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24740] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
2897391
CVSS
4.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/01
Description [CVE-2024-24741] Missing Authorization check in SAP Master Data Governance Material
3237638
CVSS
4.3

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-25643] Missing authorization check in SAP Fiori app ("My Overtime Requests")
3158455
CVSS
4.1

Affected system type ABAP
Patchday 2024-02
Released on 2024/02/13
Description [CVE-2024-24742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3413475
CVSS
9.1

Affected system type SAP Edge Integration
Patchday 2024-01
Released on 2024/01/09
Description [Multiple CVEs] Escalation of Privileges in SAP Edge Integration Cell
3412456
CVSS
9.1

Affected system type BTP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-49583] Escalation of Privileges in applications developed through SAP Business Application Studio, SAP Web IDE Full-Stack and SAP Web IDE for SAP HANA
3411869
CVSS
8.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21737] Code Injection vulnerability in SAP Application Interface Framework (File Adapter)
3389917
CVSS
7.5

Affected system type Kernel
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2023-44487] Denial of service (DOS) in SAP Web Dispatcher, SAP NetWeaver Application server ABAP, and ABAP Platform
3386378
CVSS
7.4

Affected system type SAP GUI / Frontend
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22125] Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
3407617
CVSS
7.3

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21735] Improper Authorization check in SAP LT Replication Server
3260667
CVSS
6.4

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21736] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
3387737
CVSS
4.1

Affected system type ABAP
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21738] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
3392626
CVSS
4.1

Affected system type Kernel / Web Dispatcher
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-22124] Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
3190894
CVSS
3.7

Affected system type SAP Marketing
Patchday 2024-01
Released on 2024/01/09
Description [CVE-2024-21734] URL Redirection vulnerability in SAP Marketing (Contacts App)
3411067
CVSS
9.1

Affected system type BTP
Patchday 2023-12
Released on 2023/12/12
Description [Multiple CVEs] Escalation of Privileges in SAP Business Technology Platform (BTP) Security Services Integration Libraries
3399691
CVSS
9.1

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description Update 1 to 3350297 - [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)
3394567
CVSS
8.1

Affected system type SAP Commerce
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-42481] Improper Access Control vulnerability in SAP Commerce Cloud
3382353
CVSS
7.5

Affected system type BI/BO platform
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-42478] Cross site scripting vulnerability in SAP BusinessObjects Business Intelligence Platform
3385711
CVSS
7.3

Affected system type SAP GUI / Frontend
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49580] Information disclosure vulnerability in SAP GUI for WIndows and SAP GUI for Java
3406244
CVSS
7.1

Affected system type Android
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-6542] Missing Authorization Check in SAP EMARSYS SDK ANDROID
3369353
CVSS
6.8

Affected system type BI/BO platform
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-42476] Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence
3395306
CVSS
6.4

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49587] Command Injection vulnerability in SAP Solution Manager
3217087
CVSS
6.1

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49577] Cross-Site Scripting (XSS) vulnerability in the SAP HCM (SMART PAYE solution)
3383321
CVSS
6.1

Affected system type Java
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-42479] Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct
3159329
CVSS
5.3

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description Denial of service (DoS) vulnerability in JSZip library bundled within SAPUI5
3406786
CVSS
4.3

Affected system type SAP UI5
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49584] Client-Side Desynchronization vulnerability in SAP Fiori Launchpad
3392547
CVSS
4.1

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3363690
CVSS
3.5

Affected system type ABAP
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49058] Directory Traversal vulnerability in SAP Master Data Governance
3362463
CVSS
3.5

Affected system type SAP Cloud Connector
Patchday 2023-12
Released on 2023/12/12
Description [CVE-2023-49578] Denial of service (DOS) in SAP Cloud Connector
3355658
CVSS
9.6

Affected system type SAP Business One
Patchday 2023-11
Released on 2023/11/14
Description [CVE-2023-31403] Improper Access Control vulnerability in SAP Business One product installation
3362849
CVSS
5.3

Affected system type Kernel
Patchday 2023-11
Released on 2023/11/14
Description [CVE-2023-41366] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3366410
CVSS
5.3

Affected system type Java
Patchday 2023-11
Released on 2023/11/14
Description [CVE-2023-42480] Information Disclosure in NetWeaver AS Java Logon
3372991
CVSS
6.8

Affected system type BI/BO platform
Patchday 2023-10
Released on 2023/10/10
Description [CVE-2023-42474] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence
3357154
CVSS
6.5

Affected system type SAP PowerDesigner
Patchday 2023-10
Released on 2023/10/10
Description [CVE-2023-40310] Missing XML Validation vulnerability in SAP PowerDesigner Client (BPMN2 import)
3333426
CVSS
6.5

Affected system type Java
Patchday 2023-10
Released on 2023/10/26
Description [CVE-2023-42477] Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)
3371873
CVSS
5.3

Affected system type Java
Patchday 2023-10
Released on 2023/10/10
Description Update 1 to Security Note 3324732: [CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)
3222121
CVSS
4.3

Affected system type ABAP
Patchday 2023-10
Released on 2023/10/10
Description [CVE-2023-42475] Information Disclosure Vulnerability in Statutory Reporting
3338380
CVSS
4.3

Affected system type SAP Business One
Patchday 2023-10
Released on 2023/10/10
Description [CVE-2023-41365] Information Disclosure vulnerability in SAP Business One (B1i)
3320355
CVSS
9.9

Affected system type SAP BI
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40622] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management)
3340576
CVSS
9.8

Affected system type Kernel, HANA...
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40309] Missing Authorization check in SAP CommonCryptoLib
3370490
CVSS
8.7

Affected system type BI/BO platform
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-42472] Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
3327896
CVSS
7.5

Affected system type Kernel
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40308] Memory Corruption vulnerability in SAP CommonCryptoLib
3357163
CVSS
6.3

Affected system type PowerDesigner
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40621] Code Injection vulnerability in SAP PowerDesigner Client
3317702
CVSS
6.2

Affected system type BI/BO platform
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40623] Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer)
3349805
CVSS
5.7

Affected system type Java
Patchday 2023-09
Released on 2023/09/12
Description Denial of service (DOS) vulnerability due to the usage of vulnerable version of Commons File Upload in SAP Quotation Management Insurance (FS-QUO)
3323163
CVSS
5.5

Affected system type ABAP
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40624] Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)
3326361
CVSS
5.4

Affected system type ABAP
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-40625] Missing Authorization check in Manage Purchase Contracts App
3352453
CVSS
5.3

Affected system type BI/BO platform
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-37489] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
3348142
CVSS
5.3

Affected system type Java
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-41367] Missing Authentication check in SAP NetWeaver (Guided Procedures)
3369680
CVSS
3.5

Affected system type ABAP
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-41369] External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application)
3355675
CVSS
2.7

Affected system type ABAP
Patchday 2023-09
Released on 2023/09/12
Description [CVE-2023-41368] Insecure Direct Object Reference (IDOR) vulnerability in SAP S/4HANA (Manage checkbook apps)
3341460
CVSS
9.8

Affected system type SAP PowerDesigner
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37483] Multiple Vulnerabilities in SAP PowerDesigner
3350297
CVSS
9.1

Affected system type ABAP
Patchday 2023-08
Released on 2023/07/11
Description [CVE-2023-36922] OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)
3346500
CVSS
8.8

Affected system type SAP Commerce Cloud
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-39439] Improper authentication in SAP Commerce Cloud
3341599
CVSS
7.8

Affected system type SAP PowerDesigner
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-36923] Code Injection vulnerability in SAP PowerDesigner
3358300
CVSS
7.6

Affected system type SAP Business One
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-39437] Cross-Site Scripting (XSS) vulnerability in SAP Business One
3317710
CVSS
7.6

Affected system type BI/BO platform
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37490] Binary hijack in SAP BusinessObjects Business Intelligence Suite (installer)
3312047
CVSS
7.5

Affected system type BI/BO platform
Patchday 2023-08
Released on 2023/08/08
Description Denial of Service (DoS) vulnerability due to the usage of vulnerable version of Commons FileUpload in SAP BusinessObjects Business Intelligence Platform (CMC)
3344295
CVSS
7.5

Affected system type Kernel
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37491] Improper Authorization check vulnerability in SAP Message Server
3337797
CVSS
7.1

Affected system type SAP Business One
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-33993] SQL Injection vulnerability in SAP Business One (B1i Layer)
2032723
CVSS
6.3

Affected system type ABAP
Patchday 2023-08
Released on 2014/11/11
Description Switchable authorization checks for RFC in SRM
3350494
CVSS
6.1

Affected system type Java
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37488] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Process Integration
3149794
CVSS
6.1

Affected system type SAP UI5
Patchday 2023-08
Released on 2023/08/08
Description Cross-Site Scripting (XSS) vulnerabilities in jQuery-UI library bundled with SAPUI5
3156972
CVSS
6.1

Affected system type ABAP
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-40306] URL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)
3341934
CVSS
5.9

Affected system type SAP Commerce Cloud
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37486] Information Disclosure vulnerability in SAP Commerce (OCC API)
2067220
CVSS
5.8

Affected system type ABAP
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-39436] Information Disclosure in SAP Supplier Relationship Management
3333616
CVSS
5.3

Affected system type SAP Business One
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37487] Security Misconfiguration vulnerability in SAP Business One (Service Layer)
3348000
CVSS
4.9

Affected system type ABAP
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-37492] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
3312586
CVSS
4.4

Affected system type BI/BO platform
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-39440] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform
3358328
CVSS
3.7

Affected system type SAP Host Agent
Patchday 2023-08
Released on 2023/08/08
Description [CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent
3331376
CVSS
8.7

Affected system type ABAP
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-33989] Directory Traversal vulnerability in SAP NetWeaver (BI CONT ADD ON)
3233899
CVSS
8.6

Affected system type Kernel
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-33987] Request smuggling and request concatenation vulnerability in SAP Web Dispatcher
3331029
CVSS
7.8

Affected system type Sybase platform
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-33990] Denial of service (DOS) vulnerability in SAP SQL Anywhere
3340735
CVSS
7.7

Affected system type Kernel
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-35871] Memory Corruption vulnerability in SAP Web Dispatcher
3348145
CVSS
7.2

Affected system type Java
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-36921] Header Injection in SAP Solution Manager (Diagnostic Agent)
3352058
CVSS
7.2

Affected system type Java
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-36925] Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)
3343564
CVSS
6.5

Affected system type Java
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-35872] Missing Authentication check in SAP NetWeaver Process Integration (Message Display Tool)
3343547
CVSS
6.5

Affected system type Java
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-35873] Missing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench)
3341211
CVSS
6.3

Affected system type ABAP
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-35870] Improper Access Control in SAP S/4HANA (Manage Journal Entry Template)
3326769
CVSS
6.1

Affected system type SAP Enable Now
Patchday 2023-07
Released on 2023/07/11
Description [Multiple CVEs] Multiple Vulnerabilities in SAP Enable Now
3318850
CVSS
6.0

Affected system type Kernel
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-35874] Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
3320702
CVSS
5.9

Affected system type BI/BO platform
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-36917] Password Change rate limit bypass in SAP BusinessObjects Business Intelligence Platform
3324732
CVSS
5.3

Affected system type Java
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-31405] Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)
3351410
CVSS
4.9

Affected system type ABAP
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-36924] Log Injection vulnerability in SAP ERP Defense Forces and Public Security
3088078
CVSS
4.5

Affected system type BI/BO platform
Patchday 2023-07
Released on 2023/07/11
Description [CVE-2023-33992] Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA
3324285
CVSS
8.2

Affected system type SAP UI5
Patchday 2023-06
Released on 2023/06/13
Description [CVE-2023-33991] Stored Cross-Site Scripting vulnerability in SAP UI5 (Variant Management)
3318657
CVSS
6.4

Affected system type Java
Patchday 2023-06
Released on 2023/06/13
Description [CVE-2023-33984] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Design Time Repository)
3322800
CVSS
6.1

Affected system type ABAP
Patchday 2023-06
Released on 2023/06/13
Description Update 1 to security note 3315971 - [CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3331627
CVSS
6.1

Affected system type Java
Patchday 2023-06
Released on 2023/06/13
Description [CVE-2023-33985] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Enterprise Portal)
2826092
CVSS
6.1

Affected system type ABAP
Patchday 2023-06
Released on 2023/06/13
Description [CVE-2023-33986] Cross-Site Scripting (XSS) vulnerability in SAP CRM ABAP (Grantor Management)
3325642
CVSS
2.7

Affected system type ABAP
Patchday 2023-06
Released on 2023/06/13
Description [CVE-2023-32114] Denial of Service in SAP NetWeaver (Change and Transport System)
3328495
CVSS
9.8

Affected system type Reprise License Manager
Patchday 2023-05
Released on 2023/05/09
Description Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager
3307833
CVSS
9.1

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-28762] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Console)
3323415
CVSS
8.2

Affected system type SAP Integrated...
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-29080] Privilege escalation vulnerability in SAP IBP, add-in for Microsoft Excel
3317453
CVSS
8.2

Affected system type Java
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-30744] Improper access control during application start-up in SAP AS NetWeaver JAVA
3301942
CVSS
7.9

Affected system type SAP Plant Connectivity
Patchday 2023-05
Released on 2023/05/23
Description [CVE-2023-2827] Missing Authentication in SAP Plant Connectivity and Production Connector for SAP Digital Manufacturing
3300624
CVSS
7.5

Affected system type SAP PowerDesigner
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)
3321309
CVSS
7.5

Affected system type SAP Commerce
Patchday 2023-05
Released on 2023/05/09
Description Information Disclosure vulnerability in SAP Commerce (Backoffice)
3320467
CVSS
7.5

Affected system type SAP GUI / Frontend
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-32113] Information Disclosure vulnerability in SAP GUI for Windows
3320145
CVSS
7.5

Affected system type SAP Commerce
Patchday 2023-05
Released on 2023/05/09
Description Denial of service (DOS) in SAP Commerce
3326210
CVSS
7.1

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-30743] Improper Neutralization of Input in SAPUI5
3313484
CVSS
6.3

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-30740] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
3319400
CVSS
6.1

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-31406] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform
3315971
CVSS
6.1

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-30742] Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
3309935
CVSS
6.1

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-30741] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform
3315979
CVSS
5.4

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-29188] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
3312892
CVSS
5.4

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-31407] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
3038911
CVSS
5.0

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-31404] Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)
1794761
CVSS
4.2

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/23
Description [CVE-2023-32115] SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)
3302595
CVSS
3.7

Affected system type BI/BO platform
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-28764] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
2335198
CVSS
2.8

Affected system type ABAP
Patchday 2023-05
Released on 2023/05/09
Description [CVE-2023-32112] Missing Authorization Check in Vendor Master Hierarchy
3305369
CVSS
10.0

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27497] Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge and EventLogServiceCollector)
3298961
CVSS
9.8

Affected system type BI/BO platform
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28765] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )
3305907
CVSS
8.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29186] Directory Traversal vulnerability in SAP NetWeaver ( BI CONT ADD ON)
3312733
CVSS
6.8

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-26458] Information Disclosure vulnerability in SAP Landscape Management
3311624
CVSS
6.7

Affected system type SAP GUI / Frontend
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29187] DLL Hijacking vulnerability in SapSetup (Software Installation Program)
3296378
CVSS
6.5

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28763] - Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
3289994
CVSS
6.5

Affected system type Java
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-28761] Missing Authentication check in SAP NetWeaver Enterprise Portal
3275458
CVSS
6.1

Affected system type Kernel
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27499] Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
3309056
CVSS
6.0

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-27897] Code Injection vulnerability in SAP CRM
3269352
CVSS
5.4

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29189] HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
3303060
CVSS
5.3

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29185] Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)
3315312
CVSS
5.0

Affected system type Kernel
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29108] IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
3316509
CVSS
4.7

Affected system type SAP Commerce
Patchday 2023-04
Released on 2023/04/11
Description Remote Code Execution vulnerability in SAP Commerce
3115598
CVSS
4.4

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29109] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
3301457
CVSS
4.3

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-1903] Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)
3113349
CVSS
3.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29110] Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
3114489
CVSS
3.7

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29112] Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring)
3117978
CVSS
3.1

Affected system type ABAP
Patchday 2023-04
Released on 2023/04/11
Description [CVE-2023-29111] Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)
3252433
CVSS
9.9

Affected system type Java
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-23857] Improper Access Control in SAP NetWeaver AS for Java
3245526
CVSS
9.9

Affected system type BI/BO platform
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-25616] Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)
3294595
CVSS
9.6

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3283438
CVSS
9.0

Affected system type BI/BO platform
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-25617] OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)
3296476
CVSS
8.8

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27893] Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)
3294954
CVSS
8.7

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27501] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3296346
CVSS
7.4

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-26459] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform
3275727
CVSS
7.2

Affected system type SAP Host Agent
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27498] Memory Corruption vulnerability in SAPOSCOL
3284550
CVSS
6.8

Affected system type Java
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-26461] XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)
3289844
CVSS
6.8

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-25615] SQL Injection vulnerability in SAP ABAP Platform
3296328
CVSS
6.5

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27270] Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
3287120
CVSS
6.5

Affected system type BI/BO platform
Patchday 2023-03
Released on 2023/03/14
Description [Multiple CVEs] Multiple vulnerabilities in the SAP BusinessObjects Business Intelligence platform
3281484
CVSS
6.1

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-26457] Cross-Site Scripting (XSS) vulnerability in SAP Content Server
3274920
CVSS
6.1

Affected system type ABAP
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-0021] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
3302710
CVSS
6.1

Affected system type SAP Authenticator for Android
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27895] Information Disclosure vulnerability in SAP Authenticator for Android
3288096
CVSS
5.3

Affected system type Java
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-26460] Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)
3288480
CVSS
5.3

Affected system type Java
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-27268] Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)
3288394
CVSS
5.3

Affected system type Java
Patchday 2023-03
Released on 2023/03/14
Description [CVE-2023-24526] Improper Access Control in SAP NetWeaver AS Java (Classload Service)
3285757
CVSS
8.8

Affected system type SAP Host Agent
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24523] Privilege Escalation vulnerability in SAP Host Agent (Start Service)
3263135
CVSS
8.5

Affected system type BI/BO platform
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-0020] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform
3256787
CVSS
8.4

Affected system type BI/BO platform
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24530] Unrestricted Upload of File in SAP BusinessObjects Business Intelligence Platform (CMC)
3270509
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23855] URL Redirection vulnerability in SAP Solution Manager
3267442
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-0025] Cross Site Scripting in SAP Solution Manager (BSP Application)
2985905
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24524] Missing Authorization check in SAP S/4 HANA Map Treasury Correspondence Format Data
3290901
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24528] Missing Authorization Check in SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests)
3281724
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-0019] Missing Authorization check in SAP GRC (Process Control)
3265846
CVSS
6.5

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-0024] Cross Site Scripting in SAP Solution Manager (BSP Application)
3269151
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24521] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
3266751
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23852] Cross-Site Scripting (XSS) vulnerability in SAP Solution Manager 7.2
3274585
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-25614] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
3271227
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23853] URL Redirection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3268959
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [Multiple CVEs] Multiple vulnerabilities in SAP NetWeaver AS for ABAP and ABAP Platform
3282663
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24529] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application)
3293786
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23858] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3269118
CVSS
6.1

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24522] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Framework)
3275841
CVSS
5.4

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23851] Unrestricted File Upload in SAP Business Planning and Consolidation
2788178
CVSS
4.3

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-24525] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
3263863
CVSS
4.3

Affected system type BI/BO platform
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23856] Cross-Site Scripting (XSS) vulnerability in Web Intelligence Interface
3287291
CVSS
3.8

Affected system type ABAP
Patchday 2023-02
Released on 2023/02/14
Description [CVE-2023-23854] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
3275391
CVSS
9.9

Affected system type SAP Business Planning...
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0016] SQL Injection vulnerability in SAP Business Planning and Consolidation MS
3262810
CVSS
9.9

Affected system type BI/BO platform
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0022] Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)
3268093
CVSS
9.4

Affected system type Java
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0017] Improper access control in SAP NetWeaver AS for Java
3089413
CVSS
9.0

Affected system type Kernel / ABAP
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0014] Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3276120
CVSS
6.4

Affected system type SAP Host Agent
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0012] Local Privilege Escalation in SAP Host Agent (Windows)
3283283
CVSS
6.1

Affected system type ABAP
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0013] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
3266006
CVSS
5.4

Affected system type BI/BO platform
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0018] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
3251447
CVSS
4.6

Affected system type BI/BO platform
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0015] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web Intelligence)
3150704
CVSS
4.5

Affected system type ABAP
Patchday 2023-01
Released on 2023/01/10
Description [CVE-2023-0023] Information Disclosure in SAP Bank Account Management (Manage Banks)
3273480
CVSS
9.9

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41272] Improper access control in SAP NetWeaver AS Java (User Defined Search)
3239475
CVSS
9.9

Affected system type BI/BO platform
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41267] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform
3271523
CVSS
9.8

Affected system type SAP Commerce
Patchday 2022-12
Released on 2022/12/13
Description Remote Code Execution vulnerability associated with Apache Commons Text in SAP Commerce
3267780
CVSS
9.4

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41271] Improper access control in SAP NetWeaver AS Java (Messaging System)
3268172
CVSS
8.8

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41264] Code Injection vulnerability in SAP BASIS
3271091
CVSS
8.5

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41268] Privilege escalation vulnerability in SAP Business Planning and Consolidation
3248255
CVSS
8.0

Affected system type SAP Commerce
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41266] Cross-Site Scripting (XSS) vulnerability in SAP Commerce
3266846
CVSS
6.5

Affected system type SAP Disclosure Management
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41274] Missing Authorization Checks in SAP Disclosure Management
3258950
CVSS
6.1

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description Update 1 to Security Note 2872782 - [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)
3271313
CVSS
6.1

Affected system type ABAP
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41275] Offener Redirect in SAP Solutions Manager (Enterprise Search)
3262544
CVSS
6.1

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41262] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for Java (Http Provider Service)
3265173
CVSS
6.0

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41261] Improper Access Control in SAP Solution Manager (Diagnostic Agent)
3249648
CVSS
4.3

Affected system type BI/BO platform
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41263] Missing authentication check vulnerability in SAP Business Objects Business Intelligence Platform (Web intelligence)
3270399
CVSS
4.3

Affected system type Java
Patchday 2022-12
Released on 2022/12/13
Description [CVE-2022-41273] URL Redirection vulnerability in SAP Sourcing and SAP Contract Lifecycle Management
3243924
CVSS
9.9

Affected system type BI/BO platform
Exploit available
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41203] Insecure Deserialization of Untrusted Data in SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad)
3256571
CVSS
8.7

Affected system type ABAP
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform
3249990
CVSS
7.5

Affected system type SAP UI5
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2021-20223] Multiple Vulnerabilities in SQlite bundled with SAPUI5
3263436
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41211] Arbitrary Code Execution vulnerability in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer
3229987
CVSS
6.5

Affected system type Sybase platform
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41259] Denial of service (DOS) in SAP SQL Anywhere
3260708
CVSS
6.5

Affected system type SAP Financial Consolidation
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41258] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
3218159
CVSS
6.1

Affected system type SAP UI5
Patchday 2022-11
Released on 2022/11/08
Description Insufficient Session Expiration in Central Fiori Launchpad
3238042
CVSS
6.1

Affected system type Java
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41207] URL Redirection vulnerability in SAP Biller Direct
3237251
CVSS
5.5

Affected system type SAP GUI / Frontend
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41205] Code injection vulnerability in SAP GUI for Windows
3251202
CVSS
4.7

Affected system type ABAP
Patchday 2022-11
Released on 2022/11/08
Description [CVE-2022-41215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3242933
CVSS
9.9

Affected system type Java
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution
3229132
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39013] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Program Objects)
3232021
CVSS
8.1

Affected system type Sybase platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35299] Buffer Overflow in SAP SQL Anywhere and SAP IQ
3239293
CVSS
7.7

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39015] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform(AdminTools/ Query Builder)
3245928
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-10
Released on 2022/10/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Viewer
3245929
CVSS
7.0

Affected system type SAP 3D Visual Enterprise
Patchday 2022-10
Released on 2022/10/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP 3D Visual Enterprise Author
3233226
CVSS
6.8

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35296] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Version Management System)
3049899
CVSS
6.5

Affected system type SAP Enable Now
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35297] Stored Cross-Site Scripting (XSS) vulnerability in SAP Enable Now
2495712
CVSS
6.5

Affected system type ABAP
Patchday 2022-10
Released on 2022/10/11
Description Missing authorization check in SAP Automotive Solutions
3202523
CVSS
6.1

Affected system type SAP Commerce
Patchday 2022-10
Released on 2022/10/11
Description Cross-Site Scripting (XSS) vulnerability in SAP Commerce
3211161
CVSS
6.1

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-39800] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI LaunchPad)
3229425
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41206] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform / Analysis for OLAP
3248970
CVSS
4.9

Affected system type SAP Customer Data Cloud
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41209] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
3248384
CVSS
4.9

Affected system type SAP Customer Data Cloud
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-41210] Information Disclosure Vulnerability in SAP Customer Data Cloud (Gigya)
3167342
CVSS
4.8

Affected system type BI/BO platform
Patchday 2022-10
Released on 2022/10/11
Description [CVE-2022-35226] Cross-Site Scripting (XSS) vulnerability in Data Services Management Console
3234755
CVSS
4.3

Affected system type ABAP
Patchday 2022-10
Released on 2022/10/11
Description Information Disclosure vulnerability in Master Data Governance
3223392
CVSS
7.8

Affected system type SAP Business One
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35292] Windows Unquoted Service Path issue in SAP Business One
3217303
CVSS
7.7

Affected system type BI/BO platform
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39014] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
3237075
CVSS
7.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39801] Insufficient Firefighter Session Expiration in SAP GRC Access Control Emergency Access Management
3159736
CVSS
6.7

Affected system type SAP Host Agent
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35295] Privilege Escalation Vulnerability in SAPOSCOL on Unix
2634023
CVSS
6.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Missing authorization check in Consumption of CDS Views (or) OData Services in QM-QN
3229820
CVSS
6.1

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-39799] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)
3219164
CVSS
6.1

Affected system type Java
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35298] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)
3218177
CVSS
5.4

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description [CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3198137
CVSS
4.7

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Update 1 to Security Note 3165333 - [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3126968
CVSS
4.3

Affected system type ABAP
Patchday 2022-09
Released on 2022/09/13
Description Information Disclosure vulnerability in SAP CRM WebClient
3210823
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-32245] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Open Document)
3213141
CVSS
7.3

Affected system type SAP Landscape Management
Patchday 2022-08
Released on 2022/07/26
Description Information Disclosure in SAP Landscape Management
3156484
CVSS
6.5

Affected system type SAP GUI / Frontend
Patchday 2022-08
Released on 2022/08/09
Description Information Disclosure vulnerability in SAP Business Client
2522794
CVSS
6.3

Affected system type ABAP
Patchday 2022-08
Released on 2022/08/09
Description Missing Authorization check in Portugal Digital Signature
3216653
CVSS
5.3

Affected system type SAP Authenticator for Android
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-35290] Information Disclosure in SAP Authenticator for Android
3213507
CVSS
5.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-31596] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring DB)
3213524
CVSS
5.2

Affected system type BI/BO platform
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-32244] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Commentary DB)
3210566
CVSS
4.2

Affected system type SAP Enable Now
Patchday 2022-08
Released on 2022/08/09
Description [CVE-2022-35293] Missing authorization check in SAP Enable Now Manager
3221288
CVSS
8.3

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35228] Information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)
3212997
CVSS
7.6

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32249] Information Disclosure vulnerability in SAP Business One
3157613
CVSS
7.5

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-28771] Missing Authentication check in SAP Business One (License service API)
3191012
CVSS
7.4

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31593] Code Injection vulnerability in SAP Business One
3169239
CVSS
6.5

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-29619] Information Disclosure to user Administrator in SAP BusinessObjects Business Intelligence Platform 4.x
2726124
CVSS
6.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/06/28
Description Missing Authorization Check in multiple components under SAP Automotive Solutions
3207902
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35172] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3210779
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35224] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal
3208880
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35225] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3211760
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35227] Cross-Site Scripting (XSS) vulnerability in SAP NW EP WPC
3208819
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35170] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3209557
CVSS
6.1

Affected system type Java
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32247] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3194361
CVSS
6.0

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35169] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (LCM)
3167430
CVSS
5.6

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31591] Privilege Escalation vulnerability in SAP BusinessObjects (BW Publisher Service)
3213279
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31598] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects
3203079
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32246] SQL Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Visual Difference Application)
3213826
CVSS
5.4

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31597] Missing Authorization check in SAP S/4HANA(business partner extension for Spain/Slovakia)
3150454
CVSS
4.9

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3150463
CVSS
4.9

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description Information Disclosure vulnerability in ABAP Platform
3196280
CVSS
4.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-31592] Missing Authorization check in EA-DFPS
3211203
CVSS
4.3

Affected system type SAP Business One
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35168] Denial of Service vulnerability in SAP Business One
3216161
CVSS
4.3

Affected system type ABAP
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-32248] Missing Input Validation in Manage Checkbooks component of SAP S/4HANA
3220746
CVSS
3.3

Affected system type SAP 3D Visual Enterprise
Patchday 2022-07
Released on 2022/07/12
Description [CVE-2022-35171] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3158375
CVSS
8.6

Affected system type SAProuter
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform
3147498
CVSS
8.2

Affected system type Java
Patchday 2022-06
Released on 2022/06/14
Description Improper Access Control check in SAP NetWeaver basicadmin and adminadapter services
3197005
CVSS
7.8

Affected system type SAP PowerDesigner
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31590] Potential privilege escalation in SAP PowerDesigner Proxy 16.7
3134161
CVSS
6.5

Affected system type ABAP
Patchday 2022-06
Released on 2022/06/14
Description Missing Authorization check in SAP ERP HCM
3206271
CVSS
6.5

Affected system type SAP 3D Visual Enterprise
Patchday 2022-06
Released on 2022/06/14
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3197927
CVSS
6.1

Affected system type Java
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)
3194674
CVSS
5.0

Affected system type SAP Host Agent
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent
3158815
CVSS
5.0

Affected system type SAP Financial Consolidation
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31595] Privilege escalation vulnerability in SAP Financial Consolidation
3203065
CVSS
5.0

Affected system type ABAP
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31589] Segregation of Duty vulnerability in IL FI-AP File from SHAAM program.
3158619
CVSS
4.9

Affected system type Kernel
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database
3191812
CVSS
3.7

Affected system type SAP UI5
Patchday 2022-06
Released on 2022/06/14
Description Cross-Site Scripting (XSS) vulnerability in SAP Marketing Campaigns App
3190675
CVSS
3.7

Affected system type SAP UI5
Patchday 2022-06
Released on 2022/06/14
Description Unsafe use of target blank in SAP Marketing Campaigns
3202846
CVSS
3.4

Affected system type Java
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-29615] Multiple vulnerabilities associated with Apache log4j 1.x component in SAP NetWeaver Developer Studio (NWDS)
3155571
CVSS
3.2

Affected system type SAP Adaptive Server...
Patchday 2022-06
Released on 2022/06/14
Description [CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE)
3189409
CVSS
9.8

Affected system type SAP Business One Cloud
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in in SAP Business One Cloud
3145046
CVSS
8.3

Affected system type Kernel
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)
2998510
CVSS
7.8

Affected system type BI/BO platform
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-28214] Central Management Server Information Disclosure in Business Intelligence Update
3165801
CVSS
6.5

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29611] Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
3164677
CVSS
6.5

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29613] Information Disclosure vulnerability in SAP Employee Self Service(Fiori My Leave Request)
2754555
CVSS
6.3

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments back-end
2756188
CVSS
6.3

Affected system type SAP UI5
Patchday 2022-05
Released on 2022/05/10
Description Cross-Site Request Forgery (CSRF) vulnerability in F0673 Approve Bank Payments front-end
3146336
CVSS
5.4

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3145702
CVSS
5.3

Affected system type SAP Host Agent Kernel
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform
3158188
CVSS
5.3

Affected system type SAP Host Agent
Patchday 2022-05
Released on 2022/05/10
Description [CVE-2022-28774] Information Disclosure vulnerability in SAP Host Agent logfile
3143161
CVSS
4.3

Affected system type ABAP
Patchday 2022-05
Released on 2022/05/10
Description Missing Authorization check for UI5 flexibility key user functionality
3171258
CVSS
9.8

Affected system type SAP Commerce
Patchday 2022-04
Released on 2022/04/18
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Commerce
3189635
CVSS
9.8

Affected system type SAP Customer...
Patchday 2022-04
Released on 2022/04/14
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Profitability Analytics
3189428
CVSS
9.8

Affected system type SAP HANA Platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP HANA Extended Application Services
3189429
CVSS
9.8

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in PowerDesigner Web (up to including 16.7 SP05 PL01)
3170990
CVSS
9.8

Affected system type Any
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Central Security Note for Remote Code Execution vulnerability associated with Spring Framework
3187290
CVSS
9.8

Affected system type SAP Customer Checkout
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22965] Remote Code Execution vulnerability associated with Spring Framework used in SAP Customer Checkout
3158613
CVSS
9.1

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description Update 1 to Security Note 3022622 - [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
3130497
CVSS
8.2

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27671] CSRF token visible in one of the URL in SAP Business Intelligence Platform.
3111311
CVSS
7.5

Affected system type Kernel
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28772]Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
3155609
CVSS
7.0

Affected system type SAP Commerce
Patchday 2022-04
Released on 2022/04/12
Description Privilege escalation vulnerability in Apache Tomcat server component of SAP Commerce
3137191
CVSS
6.8

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-22541] Information Disclosure vulnerability in SAP BusinessObjects Platform
3148377
CVSS
6.5

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28217] Missing XML Validation vulnerability in SAP NW EP WPC
3148094
CVSS
6.5

Affected system type Sybase platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27670] Denial of service (DOS) in SQL Anywhere
3143437
CVSS
6.5

Affected system type SAP 3D Visual Enterprise
Patchday 2022-04
Released on 2022/04/12
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3126557
CVSS
6.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28770] Cross-Site Scripting (XSS) vulnerability in SAPUI5 (vbm library)
3163583
CVSS
6.1

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-26105] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3163703
CVSS
6.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description Multiple Vulnerabilities in URI.js bundled with SAPUI5
3132633
CVSS
5.4

Affected system type SAP GUI / Frontend
Patchday 2022-04
Released on 2022/04/12
Description Information Disclosure vulnerability in SAP GUI for Windows
3055044
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28213] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (dswsbobje - SOAP Web services)
3152442
CVSS
5.3

Affected system type Java
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27669] Missing Authentication check in XML Data Archiving Service
3145769
CVSS
5.3

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27667] Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (CMC)
3111293
CVSS
4.9

Affected system type Kernel
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager)
3165333
CVSS
4.7

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28215] URL Redirection vulnerability in SAP NetWeaver ABAP Server and ABAP Platform
3165856
CVSS
4.3

Affected system type SAP Innovation Management
Patchday 2022-04
Released on 2022/03/28
Description [CVE-2022-27658] Missing authorization check in SAP Innovation Management
3150845
CVSS
4.3

Affected system type BI/BO platform
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-28216] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
3101986
CVSS
4.1

Affected system type ABAP
Patchday 2022-04
Released on 2022/04/12
Description Prepare CSP support for On-Premise down port for code dependency in SAP CRM WebClient UI
3138299
CVSS
4.1

Affected system type Adobe LiveCycle Designer
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2021-44832] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
3159091
CVSS
2.7

Affected system type SAP Solution Manager...
Patchday 2022-04
Released on 2022/04/12
Description [CVE-2022-27657] Directory Traversal vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
3154684
CVSS
10.0

Affected system type SAP Work Manager
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Work Manager
3145987
CVSS
9.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)
3149805
CVSS
8.1

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26101] Cross-Site Scripting (XSS) vulnerability in SAP Fiori launchpad
3146260
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24397] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3146261
CVSS
6.1

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24395] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3145997
CVSS
5.4

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26102] Missing authorization check in SAP NetWeaver Application Server for ABAP
3147283
CVSS
5.4

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24399] Cross-Site Scripting (XSS) vulnerability in SAP Focused Run (Real User Monitoring)
3144941
CVSS
5.4

Affected system type SAP Financial Consolidation
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26104] Missing Authorization check in SAP Financial Consolidation
1753378
CVSS
5.3

Affected system type Java
Patchday 2022-03
Released on 2013/08/13
Description Directory traversal in Web Container
3147102
CVSS
5.3

Affected system type SAP Solution Manager...
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-22547] Information Disclosure vulnerability in SAP Focused Run (Simple Diagnostics Agent 1.0)
3103424
CVSS
5.0

Affected system type BI/BO platform
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-24398] Information Disclosure vulnerability in SAP Business Objects Business Intelligence Platform
3111110
CVSS
4.8

Affected system type SAPCAR
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26100] Denial of service (DOS) in SAPCAR
3132360
CVSS
3.7

Affected system type Java
Patchday 2022-03
Released on 2022/03/08
Description [CVE-2022-26103] Information Disclosure vulnerability in SAP NetWeaver(Real Time Messaging Framework)
3104349
CVSS
3.3

Affected system type ABAP
Patchday 2022-03
Released on 2022/03/22
Description Missing authorization check in S/4HANA finance for advanced payment management
3139893
CVSS
10.0

Affected system type None
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Dynamic Authorization Management
3142773
CVSS
10.0

Affected system type SAP Commerce
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Commerce
3130920
CVSS
10.0

Affected system type SAP Data Intelligence
Patchday 2022-02
Released on 2022/01/18
Description Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Data Intelligence 3 (on-premise)
3123396
CVSS
10.0

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher
3140940
CVSS
9.1

Affected system type Java
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22544] Missing segregation of duties in SAP Solution Manager Diagnostics Root Cause Analysis Tools
3123427
CVSS
8.1

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java
3140587
CVSS
7.1

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22540] SQL Injection vulnerability in SAP NetWeaver AS ABAP (Workplace Server)
3142092
CVSS
6.5

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22542] Information Disclosure vulnerability in SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer)
3126489
CVSS
6.5

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22535] Missing Authorization check in SAP ERP HCM
2531036
CVSS
6.3

Affected system type ABAP
Patchday 2022-02
Released on 2019/04/09
Description Switchable Authorization checks for RFC BCA_DIM_RESET_TRIGGER_TABLE in Loans (FI-CAX-FS)
3140564
CVSS
5.6

Affected system type SAP Adaptive Server...
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22528] Information Disclosure in SAP Adaptive Server Enterprise
3126748
CVSS
5.4

Affected system type BI/BO platform
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22546] XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad)
3128473
CVSS
4.9

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22545] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
3124994
CVSS
4.7

Affected system type ABAP
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22534] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
3107196
CVSS
4.3

Affected system type ABAP
Patchday 2022-02
Released on 2022/01/25
Description Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver AS ABAP within Web Dynpro ABAP
3134684
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2022-02
Released on 2022/02/08
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3116223
CVSS
3.7

Affected system type Kernel
Patchday 2022-02
Released on 2022/02/08
Description [CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel)
3132515
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2022-01
Released on 2021/12/30
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services Cloud Edition
3132177
CVSS
10.0

Affected system type SAP Localization Hub
Patchday 2022-01
Released on 2021/12/22
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Localization Hub, digital compliance service for India
3136988
CVSS
10.0

Affected system type SAP IoT
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Reference Template for enabling ingestion and persistence of time series data in Azure
3132058
CVSS
10.0

Affected system type SAP IoT
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Cloud-to-Cloud Interoperability
3136094
CVSS
10.0

Affected system type SAP Digital...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Digital Manufacturing Cloud for Edge Computing
3134139
CVSS
10.0

Affected system type SAP Enterprise...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j2 component used in SAP Enterprise Continuous Testing by Tricentis
3131740
CVSS
9.8

Affected system type SAP Business One
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Business One
3112928
CVSS
8.7

Affected system type ABAP
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2022-22531] Multiple vulnerabilities in F0743 Create Single Payment application of SAP S/4HANA
3134531
CVSS
7.5

Affected system type SAP HANA Platform
Patchday 2022-01
Released on 2021/12/24
Description [CVE-2021-44228] Denial of Service vulnerability associated with Apache Log4j component used in XSA Cockpit
3135581
CVSS
6.6

Affected system type Java
Patchday 2022-01
Released on 2022/01/11
Description Update 3 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3101299
CVSS
6.6

Affected system type SAP Business One
Patchday 2022-01
Released on 2021/12/14
Description [CVE-2021-42066] Information Disclosure vulnerability in SAP Business One
3106528
CVSS
6.5

Affected system type SAP Business One
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-44234] Information Disclosure vulnerability in SAP Business One
3124597
CVSS
6.1

Affected system type SAP Enterprise Threat...
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2022-22529] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection
3131691
CVSS
5.5

Affected system type Adobe LiveCycle Designer
Patchday 2022-01
Released on 2021/12/30
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)
3133005
CVSS
5.3

Affected system type Java
Patchday 2022-01
Released on 2021/12/28
Description Update 2 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3112710
CVSS
4.3

Affected system type ABAP
Patchday 2022-01
Released on 2022/01/11
Description [CVE-2021-42067] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3132744
CVSS
10.0

Affected system type SAP BTP Kyma runtime
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Kyma
3132922
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Internet of Things Edge Platform
3132964
CVSS
10.0

Affected system type SAP Enable Now
Patchday 2021-12
Released on 2021/12/23
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Enable Now Manager
3131047
CVSS
10.0

Affected system type Any
Patchday 2021-12
Released on 2021/12/15
Description [CVE-2021-44228] Central Security Note for Remote Code Execution vulnerability associated with Apache Log4j 2 component
3132162
CVSS
10.0

Affected system type SAP API Management
Patchday 2021-12
Released on 2021/12/24
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP API Management (Tenant Cloning Tool)
3131397
CVSS
10.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/17
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
3131258
CVSS
10.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/16
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP HANA XSA
3133772
CVSS
10.0

Affected system type SAP Customer Checkout
Patchday 2021-12
Released on 2021/12/22
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Customer Checkout
3130578
CVSS
10.0

Affected system type SAP BTP Cloud Foundry runtime
Patchday 2021-12
Released on 2021/12/21
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP BTP Cloud Foundry
3132909
CVSS
10.0

Affected system type SAP Edge Services 
Patchday 2021-12
Released on 2021/12/24
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in SAP Edge Services On Premise Edition
3109577
CVSS
9.9

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description Code Execution vulnerability in SAP Commerce, localization for China
3119365
CVSS
9.9

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44231] Code Injection vulnerability in SAP ABAP Server & ABAP Platform (Translation Tools)
3130521
CVSS
9.9

Affected system type Java
Patchday 2021-12
Released on 2021/12/16
Description [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3132198
CVSS
9.8

Affected system type SAP Landscape Management
Patchday 2021-12
Released on 2021/12/20
Description [CVE-2019-17571] Code Injection vulnerability in SAP Landscape Management
3132822
CVSS
9.0

Affected system type SAP HANA Platform
Patchday 2021-12
Released on 2021/12/21
Description Update 1 to Security Note 3131397 [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in XSA Cockpit
3114134
CVSS
8.8

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42064] SQL Injection vulnerability in SAP Commerce
3102769
CVSS
8.8

Affected system type Java
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42063] Cross-Site Scripting (XSS) vulnerability in SAP Knowledge Warehouse
3123196
CVSS
8.4

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44235] Code Injection vulnerability in utility class for SAP NetWeaver AS ABAP
3131824
CVSS
8.0

Affected system type SAP Connected Health platform
Patchday 2021-12
Released on 2021/12/20
Description [CVE-2021-44228] Log4j Vulnerability in Connected Health Platform 2.0 - Fhirserver
3132074
CVSS
8.0

Affected system type SAP Cloud for Customer
Patchday 2021-12
Released on 2021/12/23
Description [CVE-2021-44228] Code Injection vulnerability in Cloud for Customer Lotus Notes PlugIn
3124094
CVSS
7.7

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44232] Directory Traversal vulnerability in SAF-T Framework
3113593
CVSS
7.5

Affected system type SAP Commerce
Patchday 2021-12
Released on 2021/12/14
Description Denial of service (DOS) in SAP Commerce
3107332
CVSS
6.6

Affected system type SAP Landscape Management
Patchday 2021-12
Released on 2021/12/14
Description Missing Authorization Check in SAP Landscape Management
2661033
CVSS
6.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/11/23
Description Missing Authorization check in RFC enabled function modules in SRM
2460948
CVSS
5.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/11/23
Description Missing Authorization Check in Vehicle Management System
2484231
CVSS
4.3

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description Missing Authorization Check in DIMP Industry Solution (Equipment and Tools Management & Bills of Services)
3121165
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-12
Released on 2021/12/14
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3103677
CVSS
4.1

Affected system type BI/BO platform
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-42061] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (Web Intelligence)
3051005
CVSS
3.5

Affected system type SAP UI5
Patchday 2021-12
Released on 2021/12/14
Description Cross-Site Scripting (XSS) Vulnerability in SAP Fiori Launchpad
3132204
CVSS
3.1

Affected system type Java
Patchday 2021-12
Released on 2021/12/16
Description Update 1 to Security Note 3130521: [CVE-2021-44228] Remote Code Execution vulnerability associated with Apache Log4j 2 component used in Java Web Service Adapter of SAP NetWeaver Process Integration
3080816
CVSS
2.4

Affected system type ABAP
Patchday 2021-12
Released on 2021/12/14
Description [CVE-2021-44233] Missing Authorization check in GRC Access Control
3099776
CVSS
9.6

Affected system type Kernel
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40501] Missing Authorization check in ABAP Platform Kernel
3110328
CVSS
8.3

Affected system type SAP Commerce
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40502] Missing Authorization check in SAP Commerce
2827086
CVSS
7.9

Affected system type SAP FRP
Patchday 2021-11
Released on 2021/11/09
Description Several security vulnerabilities in FRP 5.4.0 and FR Engine 5.4.0
3080106
CVSS
6.8

Affected system type SAP GUI / Frontend
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40503] Information Disclosure in SAP GUI for Windows
3104456
CVSS
6.5

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-42062] Missing Authorization check in SAP ERP HCM
2607126
CVSS
6.3

Affected system type Java
Patchday 2021-11
Released on 2021/11/09
Description Cross-Site Request Forgery vulnerability in Enterprise Services Repository of SAP Process Integration
3105728
CVSS
4.9

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description [CVE-2021-40504] Leverage of Permission in SAP NetWeaver Application Server for ABAP and ABAP Platform
3106859
CVSS
4.3

Affected system type ABAP
Patchday 2021-11
Released on 2021/11/09
Description URL Redirection vulnerability in Offer Management
3101406
CVSS
9.8

Affected system type Java
Patchday 2021-10
Released on 2021/10/12
Description Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance
3089438
CVSS
9.1

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/20
Description Missing transaction start (AU3) entries in the Security Audit Log
3097887
CVSS
9.1

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38178] Improper Authorization in SAP NetWeaver AS ABAP and ABAP Platform
3077635
CVSS
7.8

Affected system type SAP Success Factors
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40498] Denial of service (DOS) in the SAP SuccessFactors Mobile Application for Android devices
3074693
CVSS
6.9

Affected system type BI/BO platform
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40500] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Reports)
3074819
CVSS
6.7

Affected system type SAP Business One
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38179] Information Disclosure in SAP Business One
3080710
CVSS
6.5

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38181] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
3079427
CVSS
6.5

Affected system type SAP Business One
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38180] CSV Injection in SAP Business One
3100882
CVSS
6.4

Affected system type SAP Cloud Print Manager
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40499] Code Injection vulnerability for SAP NetWeaver Application Server for ABAP (SAP Cloud Print Manager and SAPSprint)
3055347
CVSS
6.1

Affected system type SAP UI5
Patchday 2021-10
Released on 2021/10/12
Description Cross-Site Scripting (XSS) vulnerability in SAPUI5
3084937
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-38183] Cross-Site Scripting (XSS) vulnerability in cms Service of SAP NetWeaver
2988956
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/28
Description Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA OP2020, OP1909 in Import Financial Plan Data
2988962
CVSS
5.4

Affected system type ABAP
Patchday 2021-10
Released on 2021/09/28
Description Cross-Site Request Forgery (CSRF) vulnerability for S/4HANA OP2020, OP1909 in Import Financial Plan Data
3099011
CVSS
5.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40495] Denial of Service (DOS) in SAP NetWeaver Application Server for ABAP and ABAP Platform
2655294
CVSS
5.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description Missing Authorization check in SCM BAPIs
3098917
CVSS
4.3

Affected system type BI/BO platform
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40497] Information Disclosure in SAP BusinessObjects Analysis (edition for OLAP)
3087254
CVSS
4.3

Affected system type ABAP
Patchday 2021-10
Released on 2021/10/12
Description [CVE-2021-40496] Improper Access Control in SAP NetWeaver AS ABAP and ABAP Platform
3078609
CVSS
10.0

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37535] Missing Authorization check in SAP NetWeaver Application Server for Java (JMS Connector Service)
3084487
CVSS
9.9

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
3081888
CVSS
9.9

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37531] Code Injection vulnerability in SAP NetWeaver Knowledge Management (XMLForms)
3089831
CVSS
9.9

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38176] SQL Injection vulnerability in SAP NZDT Mapping Table Framework
3073891
CVSS
9.6

Affected system type BCM platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33672] Multiple vulnerabilities in SAP Contact Center
3080567
CVSS
8.9

Affected system type Kernel
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher
3051787
CVSS
7.5

Affected system type ABAP Java HANA platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib
3082500
CVSS
6.5

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38175] Information Disclosure in SAP Analysis for Microsoft Office
3069032
CVSS
6.5

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33685] Directory Traversal vulnerability in SAP Business One
3060621
CVSS
6.1

Affected system type SAP GUI / Frontend
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38150] Information disclosure in SAP Business Client
3068582
CVSS
5.4

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38164] Missing Authorization check in in SAP ERP Financial Accounting / RFOPENPOSTING_FR
3055180
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33679] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (BI Workspace)
3070138
CVSS
5.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33686] Information Disclosure in SAP Business One
3082219
CVSS
4.8

Affected system type Java
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-21489] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3069882
CVSS
4.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-33688] SQL Injection vulnerability in SAP Business One
2308378
CVSS
4.3

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description Missing Authorization check in Financial Accounting
3075546
CVSS
4.3

Affected system type SAP Business One
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-37532] Directory Listing Enabled in SAP Business One
3087791
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-09
Released on 2021/09/14
Description [CVE-2021-38174] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3068337
CVSS
3.5

Affected system type ABAP
Patchday 2021-09
Released on 2021/09/14
Description Reverse tabnabbing vulnerability in SAP Marketing Lead Nurture Stream
3072955
CVSS
9.9

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure (Component Build Service)
3071984
CVSS
9.9

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33698] Unrestricted File Upload vulnerability in SAP Business One
3078312
CVSS
9.1

Affected system type ABAP
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33701] SQL Injection vulnerability in SAP NZDT Row Count Reconciliation
3057378
CVSS
8.8

Affected system type Kernel
Patchday 2021-08
Released on 2021/08/10
Description Missing Authentication check in SAP Web Dispatcher
3073681
CVSS
8.3

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33702] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3072920
CVSS
8.3

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33703] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3074844
CVSS
8.1

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33705] Server-Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Enterprise Portal
3067219
CVSS
7.6

Affected system type SAP Fiori Client Android
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33699] Task Hijacking in SAP Fiori Client Native Mobile for Android
3073325
CVSS
7.0

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33700] Missing Authentication check in SAP Business One
3073450
CVSS
6.9

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33691] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Notification Service)
3058553
CVSS
6.8

Affected system type SAP Cloud Connector
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33695] Multiple Vulnerabilities in SAP Cloud Connector
2659604
CVSS
6.4

Affected system type ABAP
Patchday 2021-08
Released on 2021/07/27
Description Cross-Site Scripting (XSS) Vulnerability in BSP application CRM_CM
3002517
CVSS
6.3

Affected system type ABAP
Patchday 2021-08
Released on 2021/06/08
Description [CVE-2021-21473] Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
2675775
CVSS
6.3

Affected system type ABAP
Patchday 2021-08
Released on 2021/08/10
Description Switchable Authorization checks for RFC in CRM Middleware
3078072
CVSS
6.3

Affected system type SAP Business One
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33704] Missing Authorization Check in SAP Business One (Service Layer)
3076399
CVSS
6.1

Affected system type Java
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33707] URL Redirection vulnerability in SAP NetWeaver (Knowledge Management)
3062085
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33696] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
3063048
CVSS
4.7

Affected system type BI/BO platform
Patchday 2021-08
Released on 2021/08/10
Description [CVE-2021-33697] Reverse Tabnabbing in SAP BusinessObjects Business Intelligence Platform (SAP UI5)
3007182
CVSS
9.0

Affected system type ABAP
Patchday 2021-07
Released on 2021/06/08
Description [CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
3059446
CVSS
7.6

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33671] Missing Authorization check in SAP NetWeaver Guided Procedures
3056652
CVSS
7.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33670] Denial of Service (DoS) in SAP NetWeaver AS for Java (Http Service)
3066316
CVSS
6.8

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33676] Missing authorization check in SAP CRM ABAP
3048657
CVSS
6.5

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33678] Code Injection vulnerability in SAP NetWeaver AS ABAP (Reconciliation Framework)
3044754
CVSS
6.5

Affected system type ABAP
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33677] Information Disclosure in SAP NetWeaver AS ABAP and ABAP Platform
3000663
CVSS
5.4

Affected system type Kernel
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33683] HTTP Request Smuggling in SAP Web Dispatcher and Internet Communication Manager
3053403
CVSS
5.4

Affected system type SAP Lumira Server
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33682] Cross-Site Scripting (XSS) vulnerability in SAP Lumira Server
3032624
CVSS
5.3

Affected system type Kernel
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33684] Memory Corruption in SAP NetWeaver AS ABAP and ABAP Platform
3059764
CVSS
4.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33687] Information Disclosure in SAP NetWeaver AS for Java (Enterprise Portal)
3044751
CVSS
4.3

Affected system type BI/BO platform
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33667] Information Disclosure in SAP Business Objects Web Intelligence (BI Launchpad)
3067890
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-07
Released on 2021/07/13
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3038594
CVSS
3.5

Affected system type Java
Patchday 2021-07
Released on 2021/07/13
Description [CVE-2021-33689] Insufficient Logging in SAP NetWeaver AS for JAVA (Administrator)
3053066
CVSS
8.7

Affected system type Java
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA
3030961
CVSS
6.4

Affected system type Java
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27615] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution
3021050
CVSS
5.9

Affected system type Internet Graphics Server
Patchday 2021-06
Released on 2021/06/08
Description [Multiple CVEs] Memory Corruption vulnerability in SAP Internet Graphics Service
3049879
CVSS
5.9

Affected system type SAP Enable Now
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-27637] Information Disclosure in SAP Enable Now (SAP Workforce Performance Builder - Manager)
3030604
CVSS
5.8

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33663] Plaintext Injection in SAP NetWeaver AS for ABAP
3025604
CVSS
5.4

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33664] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on Web Dynpro ABAP)
3028370
CVSS
5.4

Affected system type ABAP
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33665] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on SAP GUI for HTML)
2985562
CVSS
4.7

Affected system type SAP Commerce Cloud
Patchday 2021-06
Released on 2021/06/08
Description [CVE-2021-33666] Cross-Site Scripting (XSS) in SAP Commerce Cloud
2999590
CVSS
4.3

Affected system type ABAP
Patchday 2021-06
Released on 2021/05/25
Description Incomplete authorization checks for import of environmental data
3046610
CVSS
8.2

Affected system type ABAP
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27611] Code Injection vulnerability in SAP NetWeaver AS ABAP
3049661
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27616] Multiple vulnerabilities in SAP Business One, version for SAP HANA (Business-One-Hana-Chef-Cookbook)
3049755
CVSS
7.8

Affected system type SAP Business One
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27613] Information Disclosure in SAP Business One (Chef business-one-cookbook)
3039818
CVSS
6.5

Affected system type SAP Commerce Cloud
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27619] Information Disclosure in SAP Commerce (Backoffice search)
2114798
CVSS
6.3

Affected system type ABAP
Patchday 2021-05
Released on 2021/04/27
Description Unauthorized use of application functions in SAP GUI for HTML
2745860
CVSS
5.3

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description Information Disclosure in Enterprise Services Repository of SAP Process Integration
3012021
CVSS
4.9

Affected system type Java
Patchday 2021-05
Released on 2021/05/11
Description [Multiple CVEs] Multiple vulnerabilities in SAP Process Integration (Integration Builder Framework)
2904569
CVSS
4.6

Affected system type SAP CRM UI
Patchday 2021-05
Released on 2021/04/27
Description Cross-Site Request Forgery (CSRF) vulnerability in SAP CRM WebClient UI
3023078
CVSS
3.4

Affected system type SAP GUI / Frontend
Patchday 2021-05
Released on 2021/05/11
Description [CVE-2021-27612] SAP GUI for Windows is vulnerable to redirect users to an untrusted website
3040210
CVSS
9.9

Affected system type SAP Commerce
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27602] Remote Code Execution vulnerability in Source Rules of SAP Commerce
3017908
CVSS
8.3

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21482] Information Disclosure in SAP NetWeaver Master Data Management
3017823
CVSS
8.2

Affected system type SAP Solution Manager
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21483] Information Disclosure in SAP Solution Manager
3039649
CVSS
7.5

Affected system type SAP GUI / Frontend
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27608] Unquoted Search Path in SAPSetup
3001824
CVSS
7.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21485] Information Disclosure in SAP NetWeaver AS for Java (Telnet Commands)
3012277
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27599] Information Disclosure in SAP Process Integration (Integration Builder Framework)
3036436
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27604] Potential XXE Vulnerability in SAP Process Integration (ESR Java Mappings)
3027937
CVSS
6.5

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27598] Improper Access Control in SAP NetWeaver AS for Java (Customer Usage Provisioning Servlet)
3028729
CVSS
6.5

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27603] Denial of Service (DoS) in SAP NetWeaver AS of ABAP
3024414
CVSS
6.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27600 ] Cross-Site Scripting (XSS) vulnerability in SAP Manufacturing Execution (System Rules)
3005802
CVSS
5.4

Affected system type ABAP
Patchday 2021-04
Released on 2021/03/23
Description Cross-Site Request Forgery (CSRF) vulnerability in S/4HANA Finance for advanced payment management
2963592
CVSS
5.4

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27601] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (Applications based on HTMLB for Java)
3036679
CVSS
5.3

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description Update 1 to Security Note 1576763: Potential information disclosure relating to usernames
2911863
CVSS
5.3

Affected system type BI/BO platform
Patchday 2021-04
Released on 2021/04/13
Description Information Disclosure in BOE/CMC application
2818965
CVSS
4.6

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description Clickjacking vulnerability in Runtime Workbench of SAP Process Integration
3030948
CVSS
4.6

Affected system type SAP Solution Manager...
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27609] Missing Authorization check in SAP Focused RUN
3025637
CVSS
4.3

Affected system type Java
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-21492] Content spoofing in NetWeaver AS Java HTTP Service
3025054
CVSS
4.3

Affected system type ABAP
Patchday 2021-04
Released on 2021/04/13
Description [CVE-2021-27605 ] Missing Authorization check in HCM Travel Management Fiori Apps V2
3035472
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-04
Released on 2021/03/18
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3022622
CVSS
9.9

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21480] Code injection vulnerability in SAP Manufacturing Integration and Intelligence
3022422
CVSS
9.6

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21481] Missing Authorization Check in SAP NetWeaver AS JAVA (MigrationService)
3017378
CVSS
7.7

Affected system type SAP HANA Platform
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21484] Possible authentication bypass in SAP HANA LDAP scenarios
3007888
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21486] Missing Authorization check in SAP Enterprise Financial Services( Bank Customer Accounts )
3023778
CVSS
6.8

Affected system type ABAP
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21487] Missing Authorization Check in Payment Engine
2983436
CVSS
6.5

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21488] Insecure deserialisation in SAP NetWeaver Knowledge Management
2475705
CVSS
6.3

Affected system type ABAP
Patchday 2021-03
Released on 2021/02/23
Description Switchable Authorization checks for RFC in In House Cash
2976947
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-21491] Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on Web Dynpro Java)
2977001
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse TabNabbing vulnerability in SAP NetWeaver Application Server Java (Applications based on HTMLB for Java)
2978151
CVSS
4.7

Affected system type Java
Patchday 2021-03
Released on 2021/03/09
Description Reverse tabnabbing issue in Unified Rendering based frameworks in NetWeaver Application Server Java
3027767
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [CVE-2021-27592] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3027758
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-03
Released on 2021/03/09
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3014121
CVSS
9.9

Affected system type SAP Commerce Cloud
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21477] Remote Code Execution vulnerability in SAP Commerce
2998173
CVSS
6.3

Affected system type SWPM
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21472] Server password not set during installation of SAP NetWeaver Master Data Management 7.1
2990992
CVSS
5.4

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description Missing Authorization Checks in the Monitor Data and My Data Collections Apps
2835240
CVSS
5.4

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration
2935791
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)
2974582
CVSS
4.7

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21478] Reverse Tabnabbing vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP)
2973428
CVSS
4.7

Affected system type Kernel
Patchday 2021-02
Released on 2021/02/09
Description Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML)
2994289
CVSS
4.1

Affected system type ABAP
Patchday 2021-02
Released on 2021/02/09
Description Reverse Tabnabbing vulnerability within SAP CRM WebClient UI
2992154
CVSS
4.1

Affected system type SAP HANA Platform
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21474] SAML Assertion Signature MD5 Digest Algorithm Vulnerability in SAP HANA Database
3000897
CVSS
4.0

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description [CVE-2021-21475] Directory Traversal vulnerability in SAP NetWeaver Master Data Management 7.1
2818963
CVSS
0.0

Affected system type Java
Patchday 2021-02
Released on 2021/02/09
Description Clickjacking vulnerability in Adapter Runtime of SAP Process Integration
2999854
CVSS
9.9

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21466] Code Injection in SAP Business Warehouse and SAP BW/4HANA
2986980
CVSS
9.9

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21465] Multiple vulnerabilities in SAP Business Warehouse (Database Interface)
3001373
CVSS
8.9

Affected system type Central Order
Patchday 2021-01
Released on 2020/12/22
Description Information Disclosure in Central Order
3000306
CVSS
7.5

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21446] Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform
2743329
CVSS
6.3

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description Switchable authorization checks for RFC module in In-House-Cash.
2665387
CVSS
5.5

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description Cross-Site Request Forgery (CSRF) vulnerability in Cash Management
2965154
CVSS
5.4

Affected system type BI/BO platform
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21447] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
2984034
CVSS
5.4

Affected system type SAP Commerce Cloud
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21445] Header Manipulation vulnerability in SAP Commerce Cloud
2993032
CVSS
5.3

Affected system type Java
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21469] Information Disclosure in SAP NetWeaver Master Data Management
2992269
CVSS
5.3

Affected system type SAP GUI / Frontend
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21448] Information Disclosure in SAP GUI for Windows
3002617
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2021-01
Released on 2021/01/12
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
3008422
CVSS
4.3

Affected system type ABAP
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21467] Missing Authorization check in SAP Banking Services (Generic Market Data)
3000291
CVSS
3.6

Affected system type Analysis for Office
Patchday 2021-01
Released on 2021/01/12
Description [CVE-2021-21470] XML External Entity vulnerability in SAP EPM add-in
2974774
CVSS
10.0

Affected system type Java
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26829] Missing Authentication Check in SAP NetWeaver AS JAVA (P2P Cluster Communication)
2989075
CVSS
9.6

Affected system type BI/BO platform
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
2983367
CVSS
9.1

Affected system type ABAP
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26838] Code Injection vulnerability in SAP Business Warehouse (Master Data Management) and SAP BW4HANA
2983204
CVSS
8.5

Affected system type SAP Solution Manager
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26837] Multiple Vulnerabilities in SAP Solution Manager 7.2 (User Experience Monitoring)
2993132
CVSS
7.6

Affected system type ABAP
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26832] Missing Authorization check in SAP NetWeaver AS ABAP and SAP S4 HANA (SAP Landscape Transformation)
2974330
CVSS
6.5

Affected system type Java
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26826] Unrestricted File Upload vulnerability in SAP NetWeaver Application Server for Java (Process Integration Monitoring)
2989719
CVSS
6.3

Affected system type ABAP
Patchday 2020-12
Released on 2020/11/24
Description Missing Authorization check in S/4HANA (Central Finance)
2971163
CVSS
5.4

Affected system type Java
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26816] Missing Encryption in SAP NetWeaver AS Java (Key Storage Service)
2971180
CVSS
5.4

Affected system type SAP Disclosure Management
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26828] Formula Injection in SAP Disclosure Management
2996479
CVSS
5.3

Affected system type ABAP
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26835] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP
2978768
CVSS
4.2

Affected system type HANA platform
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26834 ] Improper authentication in SAP HANA database
2938650
CVSS
3.4

Affected system type ABAP
Patchday 2020-12
Released on 2020/12/08
Description [CVE-2020-26836] Open Redirect in SAP Solution Manager (Trace Analysis)
2985866
CVSS
10.0

Affected system type Java
Patchday 2020-11
Released on 2020/11/10
Description [Multiple CVE IDs] Missing Authentication Check in SAP Solution Manager (JAVA stack)
2982840
CVSS
9.8

Affected system type SAP Data Services
Patchday 2020-11
Released on 2020/11/10
Description Multiple Vulnerabilities in SAP Data Services
2973735
CVSS
9.1

Affected system type ABAP
Patchday 2020-11
Released on 2020/11/11
Description [CVE-2020-26808] Code Injection in SAP AS ABAP and S/4 HANA (DMIS)
2979062
CVSS
9.1

Affected system type Java
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)
2984627
CVSS
8.6

Affected system type ABAP
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26815] Security Vulnerabilities in SAP Fiori Launchpad (NewsTile Application)
2975189
CVSS
7.5

Affected system type SAP Commerce Cloud
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26809] Information Disclosure in SAP Commerce Cloud
2975170
CVSS
7.5

Affected system type SAP Commerce Cloud
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26810] Multiple Vulnerabilities in SAP Commerce Cloud (Accelerator Payment Mock)
2971954
CVSS
6.5

Affected system type ABAP
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26818] Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro)
2264508
CVSS
5.4

Affected system type ABAP
Patchday 2020-11
Released on 2020/10/27
Description SQL Injection in SAF-T Portugal
2824209
CVSS
5.4

Affected system type Java
Patchday 2020-11
Released on 2020/11/10
Description Clickjacking vulnerability in SAP Process Integration (Integration Builder Framework)
2319577
CVSS
5.4

Affected system type ABAP
Patchday 2020-11
Released on 2020/10/27
Description SQL Injection in SAF-T Portugal
2952084
CVSS
4.9

Affected system type Java
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26814] Information Disclosure in SAP Process Integration (PGP Module – Business-to-Business Add On)
2971112
CVSS
4.4

Affected system type SAP ERP Client for E-Bilanz
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26807] Incorrect Default Permissions in SAP ERP Client for E-Bilanz 1.0
2985094
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-26817] Improper input validation in Visual Enterprise Viewer
2944188
CVSS
4.3

Affected system type ABAP
Patchday 2020-11
Released on 2020/11/10
Description [CVE-2020-6316] Missing Authorization Check in SAP ERP and SAP S/4 HANA
2947891
CVSS
3.0

Affected system type ABAP
Patchday 2020-11
Released on 2020/11/10
Description Missing Authorization check in Disbursement Read API used in Read Disbursement Webservice
2969828
CVSS
10.0

Affected system type Wily Introscope
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)
2972661
CVSS
8.2

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6367] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework
2969457
CVSS
7.6

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6366] Missing XML Validation in SAP NetWeaver (Compare Systems)
2971638
CVSS
7.5

Affected system type SAP Solution Manager...
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run)
2883638
CVSS
6.5

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description Information Disclosure in Supplier Relationship Management
2956398
CVSS
6.1

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6319] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java
2973497
CVSS
5.7

Affected system type SAP 3D Visual Enterprise
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6315] Multiple Vulnerabilities in SAP 3D Visual Enterprise Viewer
2960825
CVSS
5.4

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6368] Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
2873099
CVSS
5.4

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description Missing Authorization check in EHS Task Definition attachments
2917381
CVSS
5.4

Affected system type SAP Commerce Cloud
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6272] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud
2943844
CVSS
5.3

Affected system type BI/BO platform
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6308] Server-Side Request Forgery vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Services)
2939419
CVSS
4.8

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6370] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (DI Design Time Repository)
2965315
CVSS
4.7

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6365] Reverse Tabnabbing vulnerability in SAP NetWeaver AS Java Start Page
2945581
CVSS
4.7

Affected system type SAP CRM UI
Patchday 2020-10
Released on 2020/09/22
Description Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
2606194
CVSS
4.4

Affected system type ABAP
Patchday 2020-10
Released on 2020/09/09
Description Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center
2960329
CVSS
4.4

Affected system type Java
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6323] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (Fiori Framework Page)
2953212
CVSS
4.3

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6362] Incorrect Authorization in SAP Banking Services
2955963
CVSS
4.3

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description Cross-Site Request Forgery (CSRF) in SAP Marketing
2963137
CVSS
4.3

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6371] Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint
2965287
CVSS
3.7

Affected system type SAP Commerce Cloud
Patchday 2020-10
Released on 2020/10/13
Description [CVE-2020-6363] Insufficient Session Expiration in SAP Commerce Cloud
2973100
CVSS
3.6

Affected system type ABAP
Patchday 2020-10
Released on 2020/10/13
Description Missing Authorization check in Manage Substitutions - Products and Manage Exclusions - Products
2961991
CVSS
9.6

Affected system type SAP Marketing
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6320] Improper Access Control in SAP Marketing (Mobile Channel Servlet)
2958563
CVSS
9.1

Affected system type ABAP
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6318] Code Injection vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform
2924859
CVSS
6.5

Affected system type ABAP
Patchday 2020-09
Released on 2020/08/25
Description Missing Authorization check in Discrete Industries and Mill Products
2951325
CVSS
6.5

Affected system type ABAP
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6311] Improper Authorization Checks in Banking services from SAP Bank Analyzer and SAP S/4HANA Financial Products
2934451
CVSS
6.4

Affected system type SAP Commerce Cloud
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6302] Session Fixation in SAP Commerce
2531082
CVSS
6.3

Affected system type ABAP
Patchday 2020-09
Released on 2019/03/12
Description Switchable Authorization checks for RFC BCA_DIM_LOANS_APPLOG_UPDATE in Loans (FI-CAX-FS)
2948239
CVSS
6.1

Affected system type ABAP
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6324] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (BSP Test Application)
2953112
CVSS
5.4

Affected system type Java
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6326] Cross-Site Scripting (XSS) vulnerabilities in SAP NetWeaver AS Java
2930128
CVSS
5.4

Affected system type BI/BO platform
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6325] Multiple Vulnerabilities in SAP BusinessObjects Business Intelligence Platform
2865229
CVSS
4.8

Affected system type SAP UI5
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6283] Cross-Site Scripting (XSS) vulnerability in SAP Fiori(Launchpad)
2960815
CVSS
4.3

Affected system type SAP 3D Visual Enterprise
Patchday 2020-09
Released on 2020/09/08
Description [Multiple CVEs] Improper Input Validation in SAP 3D Visual Enterprise Viewer
2953203
CVSS
2.6

Affected system type SAP Adaptive Server...
Patchday 2020-09
Released on 2020/09/08
Description [CVE-2020-6317] Information Disclosure in SAP Adaptive Server Enterprise
2928635
CVSS
9.0

Affected system type Java
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6284] Cross-Site Scripting (XSS) in SAP NetWeaver (Knowledge Management)
2927956
CVSS
8.5

Affected system type BI/BO platform
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6294] Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
2941667
CVSS
8.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6296] Code Injection Vulnerability in SAP NetWeaver (ABAP) and ABAP Platform
2939685
CVSS
8.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6298] Missing Authorization check in SAP Banking Services (Generic Market Data)
2941315
CVSS
7.5

Affected system type Java
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6309] Missing Authentication check in SAP NetWeaver AS JAVA
2938162
CVSS
7.3

Affected system type Java
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6293] Unrestricted File Upload in SAP NetWeaver (Knowledge Management)
2941332
CVSS
7.0

Affected system type SAP Adaptive Server...
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6295] Information Disclosure in SAP Adaptive Server Enterprise
2940823
CVSS
6.3

Affected system type SAP Data Hub
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6297] Information Disclosure in SAP Data Intelligence
2756551
CVSS
6.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description Missing Authorization check in TSW Supply Chain Visualization
2941170
CVSS
6.1

Affected system type SAP GUI / Frontend
Patchday 2020-08
Released on 2020/08/11
Description Cross-Site Scripting (XSS) vulnerabilities in modified jQuery bundled with SAPUI5
2948317
CVSS
6.1

Affected system type SAP Commerce
Patchday 2020-08
Released on 2020/08/11
Description Vulnerabilities in open source libraries used in SAP Commerce
2921615
CVSS
5.5

Affected system type BI/BO platform
Patchday 2020-08
Released on 2020/08/11
Description BI Platform stores SAP BW Authentication Password as clear text
2949196
CVSS
5.4

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)
2754546
CVSS
5.0

Affected system type Lumira Designer
Patchday 2020-08
Released on 2020/08/11
Description Potential information disclosure in Lumira Designer
2925827
CVSS
4.8

Affected system type BI/BO platform
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6300] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Central Management Console)
2944988
CVSS
4.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6310] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform
2941510
CVSS
4.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform
2885671
CVSS
4.3

Affected system type ABAP
Patchday 2020-08
Released on 2020/08/11
Description [CVE-2020-6273] Missing Authorization check in SAP S/4 HANA (Fiori UI for General Ledger Accounting)
2593479
CVSS
3.9

Affected system type Java
Patchday 2020-08
Released on 2018/06/15
Description Checking server certificates and host name of managed systems
2934135
CVSS
10.0

Affected system type Java
Exploit available
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6287] Multiple Vulnerabilities in SAP NetWeaver AS JAVA (LM Configuration Wizard)
2932473
CVSS
7.7

Affected system type Java
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)
2486446
CVSS
6.3

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description Missing Authorization check in Pricat Inbound and Pricat Outbound
2537961
CVSS
6.3

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description Switchable Authorization checks for RFC in MM-PUR-GF
2758000
CVSS
6.3

Affected system type SAP Disclosure Management
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6267] Multiple vulnerabilities in SAP Disclosure Management
2603398
CVSS
6.3

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description Missing authorization check in Allocation Management
2541823
CVSS
6.3

Affected system type ABAP
Patchday 2020-07
Released on 2020/06/09
Description Switchable authorization checks for RFC in SAP CRM (external billing)
2091403
CVSS
6.3

Affected system type ABAP
Patchday 2020-07
Released on 2015/08/11
Description Directory traversal in BC-MID-ICF
2849967
CVSS
6.1

Affected system type BI/BO platform
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6276] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(Bipodata)
2917743
CVSS
6.1

Affected system type BI/BO platform
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6281] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform(BI Launch pad)
2938831
CVSS
6.0

Affected system type ABAP
Patchday 2020-07
Released on 2020/06/23
Description SESS: Duplicate AU3 entries in the Security Audit Log
2896025
CVSS
5.8

Affected system type Java
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6282] Server-Side Request Forgery in SAP NetWeaver AS JAVA (IIOP service)
2912708
CVSS
5.4

Affected system type BI/BO platform
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6278] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC)
2847817
CVSS
4.3

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description Missing Authorization check in Travel Management
2874738
CVSS
3.8

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description Missing Authorization Check in S4 ACR Brazil Option
2927373
CVSS
2.7

Affected system type ABAP
Patchday 2020-07
Released on 2020/07/14
Description [CVE-2020-6280] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform
2928570
CVSS
9.8

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description Ghostcat' Apache Tomcat AJP Vulnerability in SAP Liquidity Management for Banking
2918924
CVSS
9.8

Affected system type SAP Commerce
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub
2906366
CVSS
8.6

Affected system type SAP Commerce
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6264] Information Disclosure in SAP Commerce
2931391
CVSS
8.2

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6271] Missing XML Validation in SAP Solution Manager (Problem Context Manager)
2912939
CVSS
7.6

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6275] Server Side Request Forgery vulnerability in SAP NetWeaver AS ABAP
2878568
CVSS
6.9

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6263] Authentication Bypass in Standalone Clients connecting to SAP NetWeaver AS Java via P4 Protocol
2915126
CVSS
6.5

Affected system type Java
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6260] Incomplete XML Validation in SAP Solution Manager (Trace Analysis)
2916562
CVSS
6.5

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6270] Missing Authorization check in SAP Netweaver AS ABAP (Banking Services)
2918762
CVSS
6.5

Affected system type Adobe LiveCycle Designer
Patchday 2020-06
Released on 2020/06/09
Description Multiple vulnerabilities in Adobe LiveCycle Designer 11.0
2540180
CVSS
6.3

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Switchable Authorization checks for RFC in Environment, Health & Safety
2878935
CVSS
6.1

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE)
2911687
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
2906996
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6268] Missing authorization check in SAP ERP (Statutory Reporting for Insurance Companies)
2911704
CVSS
5.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6266] URL redirection in SAP Fiori for SAP S/4HANA
2923035
CVSS
4.4

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI
2908382
CVSS
4.4

Affected system type SAP Business One
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6239] Information Disclosure in SAP Business One (Backup Service)
2911267
CVSS
4.3

Affected system type ABAP
Patchday 2020-06
Released on 2020/06/09
Description Update 1 to Security Note 2752614 - [CVE-2019-0319] Content Injection Vulnerability in SAP Gateway
2905836
CVSS
4.3

Affected system type BI/BO platform
Patchday 2020-06
Released on 2020/06/09
Description [CVE-2020-6269] Information Disclosure in SAP Business Objects Business Intelligence Platform
2835979
CVSS
9.9

Affected system type ABAP
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6262] Code Injection vulnerability in Service Data Download
2917275
CVSS
9.1

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6248] Code injection in SAP Adaptive Server Enterprise (Backup Server)
2917090
CVSS
9.0

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6252] Information Disclosure in SAP Adaptive Server Enterprise (Cockpit)
2916927
CVSS
8.8

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise
2915585
CVSS
8.0

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6243] Code Injection in SAP Adaptive Server Enterprise (XP Server on Windows Platform)
2917273
CVSS
7.2

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)
2917022
CVSS
6.8

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6250] Information Disclosure in SAP Adaptive Server Enterprise
2920548
CVSS
6.5

Affected system type SAP Adaptive Server...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6259] Missing authorization check in SAP Adaptive Server Enterprise
2913293
CVSS
6.1

Affected system type SAP Enterprise Threat...
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6254] Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Threat Detection
2747062
CVSS
5.0

Affected system type ABAP
Patchday 2020-05
Released on 2020/05/12
Description This note has been re-released without changes. - Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP
2915429
CVSS
4.3

Affected system type SAP IDM
Patchday 2020-05
Released on 2020/05/12
Description [CVE-2020-6258] Missing Authorization check in SAP Identity Management
2904480
CVSS
9.3

Affected system type SAP Commerce Cloud
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce
2863731
CVSS
9.1

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6219] Deserialization of Untrusted Data in SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer)
2900118
CVSS
9.1

Affected system type SAP Orient DB
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6230] Code Injection vulnerability in SAP OrientDB 3.0
2896682
CVSS
9.1

Affected system type Java
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6225] Directory Traversal vulnerability in SAP NetWeaver (Knowledge Management)
2906994
CVSS
8.6

Affected system type SAP Solution Manager
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6235] Missing authentication check in SAP Solution Manager (Diagnostics Agent )
2898077
CVSS
7.5

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6237] Information Disclosure in SAP Business Objects Business Intelligence Platform (dswsbobje Web Application)
2902456
CVSS
7.2

Affected system type SAP Landscape Management
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)
2902645
CVSS
7.2

Affected system type SAP Host Agent
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6234] Privilege Escalation in SAP Host Agent
2878507
CVSS
6.4

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6195] Multiple vulnerabilities in SAP Business Objects Business Intelligence Platform
2864966
CVSS
6.3

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6212] Missing Authorization Check in SAP ERP & S/4 HANA (Egypt localized Withholding Tax reports)
2877226
CVSS
6.3

Affected system type ABAP
Patchday 2020-04
Released on 2020/03/12
Description Switchable Authorization checks in SAP Supplier Relationship Management
2826528
CVSS
6.2

Affected system type Java
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6224] Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service)
2872782
CVSS
6.1

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6215] URL Redirection vulnerability in SAP NetWeaver AS ABAP – Business Server Pages Test Application IT00
2900374
CVSS
6.1

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6229] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME)
2872545
CVSS
6.1

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6217] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application IT05)
2876059
CVSS
6.1

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6216] Cross-Site Scripting (XSS) vulnerability in SAP Business Objects Business Intelligence Platform (BILaunchpad/ Opendocument)
2872752
CVSS
6.1

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6213]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP(Business Server Pages Test Application SBSPEXT_PHTMLB)
2880804
CVSS
5.4

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6222] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
2879132
CVSS
5.4

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6226] Cross-Site Scripting (XSS) vulnerabilities in SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface)
2863396
CVSS
5.3

Affected system type BI/BO platform
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6227] Remote unauthenticated log injection in SAP Business Objects Business Intelligence Platform (CMS / Auditing issues)
2866752
CVSS
5.3

Affected system type SAP GUI / Frontend
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6228] Missing Integrity Check in SAP BUSINESS CLIENT
2888556
CVSS
5.3

Affected system type SAP Commerce Cloud
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6232] Missing Authorization check in SAP Commerce
2897612
CVSS
4.7

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6214] Incorrect Authorization in SAP S/4HANA (Financial Products Subledger)
2904796
CVSS
4.3

Affected system type ABAP
Patchday 2020-04
Released on 2020/04/14
Description [CVE-2020-6233] Missing Authorization Check in SAP S/4 HANA (Financial Products Subledger and Banking Services)
2890213
CVSS
10.0

Affected system type Java
Exploit available
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6207] Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring)
2845377
CVSS
9.8

Affected system type Java
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6198] Missing Authentication check in SAP Solution Manager (Diagnostics Agent)
2806198
CVSS
9.1

Affected system type Java
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6203] Path Manipulation in SAP NetWeaver UDDI Server(Services Registry)
2861301
CVSS
8.2

Affected system type BI/BO platform
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6208] Remote Code Execution in SAP Business Objects Business Intelligence Platform (Crystal Reports)
2826782
CVSS
7.5

Affected system type BI/BO platform
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6196] Denial of service (DOS) in SAP BusinessObjects Mobile (MobileBIService)
2858044
CVSS
7.5

Affected system type SAP Disclosure Management
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6209] Missing Authorization check in SAP Disclosure Management
1966029
CVSS
7.3

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description Directory traversal in SAP Environment Health and Safety
2660005
CVSS
7.2

Affected system type SAP MaxDB
Patchday 2020-03
Released on 2018/08/14
Description [CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache
2731871
CVSS
6.3

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description Missing Authorization check in Commercial Project Management
2876813
CVSS
6.1

Affected system type SAP Commerce Cloud
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6201] Cross-Site Scripting (XSS) vulnerability in SAP Commerce Cloud (testweb extension)
2884910
CVSS
6.1

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6205] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP Business Server Pages  (Smart Forms)
2892570
CVSS
5.9

Affected system type ABAP Development Tools
Patchday 2020-03
Released on 2020/03/10
Description Missing XML Validation vulnerability in ABAP Development Tools
2847787
CVSS
5.5

Affected system type Java
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6202] Missing XML Validation in SAP NetWeaver Application Server Java (User Management Engine)
2880664
CVSS
5.4

Affected system type SAP Enable Now
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6178] Insufficient session expiration in SAP Enable Now Manager
2876413
CVSS
5.4

Affected system type SAP Commerce Cloud
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6200] Cross-Site-Scripting in SAP Commerce Cloud (SmartEdit extension)
2871167
CVSS
5.4

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6199] Missing Authorization check in SAP ERP and S/4 HANA (MENA Certificate Management)
2864462
CVSS
4.7

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6210] Cross-Site Scripting (XSS) vulnerability in SAP Fiori Launchpad
2859004
CVSS
4.7

Affected system type SAP CPI DS
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6206] Cross-Site Request Forgery in SAP Cloud Platform Integration for data services
2841874
CVSS
4.3

Affected system type ABAP
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6204] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)
2845363
CVSS
3.8

Affected system type SAP Enable Now
Patchday 2020-03
Released on 2020/03/10
Description [CVE-2020-6197] Insufficient session expiration in SAP Enable Now Manager
2622660
CVSS
10.0

Affected system type SAP GUI / Frontend
Patchday 2020-02
Released on 2018/04/10
Description Security updates for the browser control Google Chromium delivered with SAP Business Client
2841053
CVSS
7.5

Affected system type SAP Host Agent
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6186] Denial of Service (DOS) Vulnerability in SAP Host Agent
2695776
CVSS
7.4

Affected system type SAP Mobile Platform
Patchday 2020-02
Released on 2020/01/14
Description Missing Authorization Check in SAP Mobile Platform Native SDK, Android
2878030
CVSS
7.2

Affected system type SAP Landscape Management
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6191] Missing Input Validation in SAP Landscape Management
2877968
CVSS
7.2

Affected system type SAP Landscape Management
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6192] Missing Input Validation in SAP Landscape Management
2822074
CVSS
6.6

Affected system type ABAP
Patchday 2020-02
Released on 2020/01/14
Description Missing Authorization check in SAP NetWeaver (ABAP Server)
2870067
CVSS
6.5

Affected system type ABAP
Patchday 2020-02
Released on 2020/02/11
Description Update 1 to Security Note 2736825 - [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server
2736825
CVSS
6.5

Affected system type ABAP
Patchday 2020-02
Released on 2019/03/12
Description [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server
2688383
CVSS
6.3

Affected system type ABAP
Patchday 2020-02
Released on 2020/02/11
Description Missing authorization check in Dangerous Goods Management of EHS Services in SCM
2057196
CVSS
6.3

Affected system type ABAP
Patchday 2020-02
Released on 2014/09/17
Description Missing authorization check in IS-B-BCA-AM
2857511
CVSS
6.3

Affected system type ABAP
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6188] Missing Authorization check in SAP ERP and S/4 HANA (VAT Pro-Rata reports)
2880869
CVSS
6.1

Affected system type ABAP
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6184 ]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver and SAP S/4HANA
2873012
CVSS
6.1

Affected system type Java
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6193]Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver (Knowledge Management ICE Service)
2880744
CVSS
5.8

Affected system type ABAP
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6181] HTTP Response Splitting vulnerability in SAP NetWeaver and ABAP Platform
2838835
CVSS
5.3

Affected system type Java
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6190]Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application)
2695210
CVSS
5.3

Affected system type BI/BO platform
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6189] Information Disclosure in SAP BusinessObjects BI Central Management Console
2836445
CVSS
5.3

Affected system type SAP Host Agent
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6183] Unprivileged Access to technical data using SAPOSCOL of SAP Host Agent
2864415
CVSS
4.9

Affected system type Java
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6187]Missing XML Validation vulnerability in SAP NetWeaver(Guided Procedures)
2880993
CVSS
4.3

Affected system type SAP Mobile Platform
Patchday 2020-02
Released on 2020/02/11
Description [CVE-2020-6177] Missing XML Validation vulnerability in SAP Mobile Platform
2871877
CVSS
8.3

Affected system type ABAP
Patchday 2020-01
Released on 2019/12/24
Description Multiple security vulnerabilities in SAP EAM, add-on for MRO 4.0 by HCL for SAP S/4HANA 1809
2495462
CVSS
6.3

Affected system type ABAP
Patchday 2020-01
Released on 2020/01/14
Description Switchable Authorization checks for RFC in SAP Leasing
2165892
CVSS
6.3

Affected system type ABAP
Patchday 2020-01
Released on 2020/01/14
Description Missing authorization check in Transaction Manager
2863743
CVSS
6.1

Affected system type Java
Patchday 2020-01
Released on 2020/01/14
Description [CVE-2020-6305] Cross-Site Scripting (XSS) vulnerability in Rest Adapter of SAP Process Integration
2848498
CVSS
5.9

Affected system type Kernel
Patchday 2020-01
Released on 2020/01/14
Description [CVE-2020-6304] Denial of service (DOS) in SAP NetWeaver Internet Communication Manager
2845401
CVSS
5.4

Affected system type Realtech
Patchday 2020-01
Released on 2020/01/14
Description Missing Authorization check in Realtech RTCISM 100
2772325
CVSS
5.4

Affected system type SAP Disclosure Management
Patchday 2020-01
Released on 2020/01/13
Description [CVE-2020-6303] Improper input validation in SAP Disclosure Management
2863397
CVSS
4.3

Affected system type ABAP
Patchday 2020-01
Released on 2020/01/14
Description [CVE-2020-6307] Missing Authorization Check in Automated Note Search Tool (SAP_BASIS)
2142551
CVSS
4.3

Affected system type ABAP
Patchday 2020-01
Released on 2016/07/12
Description Whitelist service for Clickjacking Framing Protection in AS ABAP
2843016
CVSS
4.3

Affected system type ABAP
Patchday 2020-01
Released on 2019/11/12
Description [CVE-2019-0388] Content spoofing vulnerability in UI5 HTTP Handler
2865348
CVSS
2.7

Affected system type ABAP
Patchday 2020-01
Released on 2020/01/14
Description [CVE-2020-6306] Missing Authorization check in SAP Leasing
2845780
CVSS
6.7

Affected system type SAP Adaptive Server...
Patchday 2019-12
Released on 2019/12/10
Description [CVE-2019-0402] Information Disclosure in SAP Adaptive Server Enterprise
2504979
CVSS
6.4

Affected system type Java
Patchday 2019-12
Released on 2019/12/10
Description Upgrade SSL support to TLSv1.2
2734675
CVSS
6.3

Affected system type ABAP
Patchday 2019-12
Released on 2019/12/10
Description Missing Authorization Check in SAP Cash Management
2830578
CVSS
5.4

Affected system type BI/BO platform
Patchday 2019-12
Released on 2019/12/10
Description [CVE-2019-0395] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad)
2745211
CVSS
5.3

Affected system type Java
Patchday 2019-12
Released on 2019/12/10
Description Information Disclosure in PI Axis Adapter
2803554
CVSS
5.3

Affected system type ABAP
Patchday 2019-12
Released on 2019/12/10
Description [CVE-2019-0399] Potential Information Disclosure in SAP Portfolio and Project Management
2845183
CVSS
5.3

Affected system type SAP Enable Now
Patchday 2019-12
Released on 2019/12/10
Description [CVE-2019-0405] Multiple Security vulnerabilities in SAP Enable Now release 1911
2814462
CVSS
5.3

Affected system type ABAP
Patchday 2019-12
Released on 2019/11/26
Description Missing Authorization Check in S/4Hana ACR Brazil Option Features
2701027
CVSS
4.3

Affected system type BI/BO platform
Patchday 2019-12
Released on 2019/12/10
Description [CVE-2019-0398] Cross-Site Request Forgery (CSRF) vulnerability in SAP BusinessObjects Business Intelligence Platform (Monitoring application)
2839864
CVSS
9.1

Affected system type Java
Patchday 2019-11
Released on 2019/11/12
Description Update 2 to Security Note 2808158: [CVE-2019-0330] OS Command Injection vulnerability in SAP Diagnostics Agent
2814007
CVSS
7.1

Affected system type BI/BO platform
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0396] Missing XML Validation vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface)
2393937
CVSS
7.1

Affected system type ABAP
Patchday 2019-11
Released on 2019/11/12
Description VMC Authority Check
2833771
CVSS
6.5

Affected system type SAP Enable Now
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0385] Cross-Site Scripting (XSS) vulnerability in SAP Enable Now
2840520
CVSS
6.3

Affected system type ABAP
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0386] - Missing authorization check in ERP Sales and SAP S/4HANA sales (SD-SLS)
2828981
CVSS
6.3

Affected system type ABAP
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0384] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)
2814357
CVSS
5.9

Affected system type Java
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0389] Privilege escalation in SAP NetWeaver Application Server Java
2816035
CVSS
5.4

Affected system type ABAP
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0393] SQL injection vulnerability in SAP Quality Management
2817937
CVSS
5.4

Affected system type BI/BO platform
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0382] XSS vulnerabilty in SAP Business Objects BI Platform (Web Intelligence)
2842034
CVSS
5.0

Affected system type SAP Data Hub
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0390] Information Disclosure in SAP Data Hub
2819170
CVSS
4.3

Affected system type ABAP
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0383] Missing Authorization check in SAP Treasury and Risk Management (Transaction Management)
2835226
CVSS
4.3

Affected system type Java
Patchday 2019-11
Released on 2019/11/12
Description [CVE-2019-0391] Information Disclosure in SAP NetWeaver Application Server Java (eCATT service)
962319
CVSS
5.3

Affected system type Java
Patchday 2019-05
Released on 2006/07/07
Description Detailed error messages with stack trace in Web Dynpro
2494184
CVSS
6.3

Affected system type Sybase platform
Patchday 2017-08
Released on 2017/08/08
Description Cross-Site Request Forgery (CSRF) vulnerability in multiple SAP Sybase products
2418823
CVSS
7.2

Affected system type ABAP
Patchday 2017-03
Released on 2017/03/14
Description Update 1 to Note 2319506
2319506
CVSS
7.2

Affected system type Oracle
Patchday 2016-08
Released on 2016/08/09
Description SQL injection vulnerability in Database Monitors for Oracle
2246277
CVSS
6.4

Affected system type Oracle
Patchday 2016-01
Released on 2016/01/12
Description SAP ORACLE insecure authentication scheme
2201710
CVSS
5.4

Affected system type Sybase platform
Patchday 2015-09
Released on 2015/09/08
Description Fixing Logjam and Alternative chains certificate forgery vulnerabilities in multiple SAP Sybase products
2129892
CVSS
9.0

Affected system type ABAP
Patchday 2015-04
Released on 2015/03/10
Description Potential Buffer overflow in PA-PAO
1298160
CVSS
9.9

Affected system type ABAP
Patchday 2009-10
Released on 2009/10/08
Description Security note: Forbidden program execution possible