Show filters
181 Total Results
Displaying 71-80 of 181
Sort by:
Attacker Value
Unknown

CVE-2022-41262

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2022-41214

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
Attacker Value
Unknown

CVE-2022-41215

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
Attacker Value
Unknown

CVE-2022-41212

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
Attacker Value
Unknown

CVE-2022-39799

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Attacker Value
Unknown

CVE-2022-35294

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
Attacker Value
Unknown

CVE-2022-29611

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Attacker Value
Unknown

CVE-2022-29610

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
Attacker Value
Unknown

CVE-2022-27669

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
Attacker Value
Unknown

CVE-2022-26103

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.