Show filters
1,715 Total Results
Displaying 141-150 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2024-34687

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
0
Attacker Value
Unknown

CVE-2024-33009

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown

CVE-2024-33008

Disclosure Date: May 14, 2024 (last updated September 26, 2024)
SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.
0
Attacker Value
Unknown

CVE-2024-33007

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.
0
Attacker Value
Unknown

CVE-2024-33004

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.
0
Attacker Value
Unknown

CVE-2024-33002

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
0
Attacker Value
Unknown

CVE-2024-33000

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.
0
Attacker Value
Unknown

CVE-2024-32733

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application
0
Attacker Value
Unknown

CVE-2024-32731

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. 
0
Attacker Value
Unknown

CVE-2024-28165

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application
0