Show filters
1,715 Total Results
Displaying 221-230 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2023-31403

Disclosure Date: November 14, 2023 (last updated September 28, 2024)
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
Attacker Value
Unknown

CVE-2023-36920

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.
Attacker Value
Unknown

CVE-2023-42477

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-42475

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
Attacker Value
Unknown

CVE-2023-42474

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.
Attacker Value
Unknown

CVE-2023-42473

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-41365

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.
Attacker Value
Unknown

CVE-2023-40310

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.
Attacker Value
Unknown

CVE-2023-38538

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
Attacker Value
Unknown

CVE-2023-38537

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.