Show filters
1,715 Total Results
Displaying 51-60 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2024-47581

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.
0
Attacker Value
Unknown

CVE-2024-47580

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.
0
Attacker Value
Unknown

CVE-2024-47579

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability
0
Attacker Value
Unknown

CVE-2024-47578

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.
0
Attacker Value
Unknown

CVE-2024-47577

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an attacker impersonating as authorized admin visits such server logs, then they get access to the customer data. The amount of leaked confidential data however is extremely limited, and the attacker has no control over what data is leaked.
0
Attacker Value
Unknown

CVE-2024-47576

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.
0
Attacker Value
Unknown

CVE-2024-32732

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.
0
Attacker Value
Unknown

CVE-2024-47595

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2024-47593

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.
0
Attacker Value
Unknown

CVE-2024-47592

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
0