Show filters
1,715 Total Results
Displaying 261-270 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2023-37486

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On successful exploitation there could be a high impact on confidentiality with no impact on integrity and availability of the application.
Attacker Value
Unknown

CVE-2023-37484

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.
Attacker Value
Unknown

CVE-2023-37483

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
Attacker Value
Unknown

CVE-2023-36926

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server.  There is no impact on integrity or availability.
Attacker Value
Unknown

CVE-2023-36923

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application.
Attacker Value
Unknown

CVE-2023-33993

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and availability of the application.
Attacker Value
Unknown

CVE-2020-10962

Disclosure Date: August 01, 2023 (last updated February 25, 2025)
In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-36925

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
Attacker Value
Unknown

CVE-2023-36924

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.
Attacker Value
Unknown

CVE-2023-36922

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.