Loading HuntDB...

SAP SE

457 Products 776 CVEs

CVE Severity Distribution (All Time)

Critical
44
High
72
Medium
298
Low
10

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2023-36920 MEDIUM 1 year, 7 months ago

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response heade…

CVE-2023-40307 MEDIUM 1 year, 8 months ago

An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer ov…

CVE-2023-40306 MEDIUM 1 year, 9 months ago

SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient UR…

CVE-2022-41203 CRITICAL 2 years, 7 months ago

In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can …

CVE-2022-41258 MEDIUM 2 years, 7 months ago

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when ru…

CVE-2022-41208 MEDIUM 2 years, 7 months ago

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter curr…

CVE-2022-41207 MEDIUM 2 years, 7 months ago

SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsens…

CVE-2022-41205 MEDIUM 2 years, 7 months ago

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr…

CVE-2022-41260 MEDIUM 2 years, 7 months ago

SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject …

CVE-2022-41214 HIGH 2 years, 7 months ago

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a …