Show filters
1,715 Total Results
Displaying 141-150 of 1,715
Sort by:
Attacker Value
Unknown
CVE-2024-34687
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
0
Attacker Value
Unknown
CVE-2024-33009
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown
CVE-2024-33008
Disclosure Date: May 14, 2024 (last updated September 26, 2024)
SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.
0
Attacker Value
Unknown
CVE-2024-33007
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
0
Attacker Value
Unknown
CVE-2024-33004
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
0
Attacker Value
Unknown
CVE-2024-33002
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown
CVE-2024-33000
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.
0
Attacker Value
Unknown
CVE-2024-32733
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application
0
Attacker Value
Unknown
CVE-2024-32731
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2024-28165
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
0