Show filters
1,715 Total Results
Displaying 241-250 of 1,715
Sort by:
Attacker Value
Unknown
CVE-2023-40622
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, and availability.
0
Attacker Value
Unknown
CVE-2023-40621
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default.
0
Attacker Value
Unknown
CVE-2023-40309
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.
0
Attacker Value
Unknown
CVE-2023-42472
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request, modify the content type and the extension to read and modify sensitive data causing a high impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2023-41369
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file gets opened in the browser to cause the entity loops to slow down the browser.
0
Attacker Value
Unknown
CVE-2023-41368
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.
0
Attacker Value
Unknown
CVE-2023-41367
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
0
Attacker Value
Unknown
CVE-2023-40308
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
0
Attacker Value
Unknown
CVE-2023-37489
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low impact on confidentiality and no impact on the application's availability or integrity.
0
Attacker Value
Unknown
CVE-2023-40306
Disclosure Date: September 08, 2023 (last updated February 25, 2025)
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
0