Show filters
181 Total Results
Displaying 71-80 of 181
Sort by:
Attacker Value
Unknown
CVE-2022-41262
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2022-41214
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2022-41215
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
0
Attacker Value
Unknown
CVE-2022-41212
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
0
Attacker Value
Unknown
CVE-2022-39799
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
0
Attacker Value
Unknown
CVE-2022-35294
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
0
Attacker Value
Unknown
CVE-2022-29611
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
0
Attacker Value
Unknown
CVE-2022-29610
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
0
Attacker Value
Unknown
CVE-2022-27669
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
0
Attacker Value
Unknown
CVE-2022-26103
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
0