Loading HuntDB...

SAP

147 Products 182 CVEs

CVE Severity Distribution (All Time)

Critical
19
High
16
Medium
64
Low
5

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 9 CVEs

Recent CVEs

View all
CVE-2024-47595 MEDIUM 7 months, 1 week ago

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t…

CVE-2024-47592 MEDIUM 7 months, 1 week ago

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This ha…

CVE-2024-47590 HIGH 7 months, 1 week ago

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious…

CVE-2024-47586 MEDIUM 7 months, 1 week ago

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could…

CVE-2024-42372 MEDIUM 7 months, 1 week ago

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted glo…

CVE-2024-45281 MEDIUM 9 months, 1 week ago

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not d…

CVE-2024-41733 MEDIUM 10 months, 1 week ago

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear…

CVE-2024-33003 HIGH 10 months, 1 week ago

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number…

CVE-2024-39597 HIGH 11 months, 2 weeks ago

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and …