Vulnerabilities in SAP

159 results
Vexday analysis

Com 159 CVEs catalogadas e nenhuma atualmente registrada no catálogo KEV da CISA, o perfil de exploração ativa do SAP situa-se abaixo da média geral do catálogo, o que representa um indicador favorável no curto prazo, mas não elimina atenção recomendada às 16 vulnerabilidades de severidade crítica. A falha mais comum é CWE-79 (Cross-Site Scripting), sugerindo que problemas de sanitização de entrada em interfaces web constituem o padrão predominante na superfície de ataque. A CVE mais perigosa no momento, CVE-2023-29186, apresenta EPSS de 0,2304 — o maior valor observado no conjunto —, indicando probabilidade não desprezível de exploração mesmo sem confirmação ativa no KEV. A existência de pelo menos um PoC público reforça a necessidade de priorizar a remediação das vulnerabilidades críticas antes que o cenário de exploração se altere.

CVE-2023-29186HIGHDirectory/Path Traversal vulnerability in SAP NetWeaver.EPSS 23.0%CVE-2023-0017CRITICALImproper access control in SAP NetWeaver AS for JavaEPSS 15.7%CVE-2023-28765CRITICALInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Promotion Management )EPSS 14.9%CVE-2023-27267CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge)EPSS 14.2%CVE-2018-2437The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions whEPSS 2.6%CVE-2018-2465SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, EPSS 2.3%CVE-2018-2449SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for validEPSS 2.0%CVE-2017-16684SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for funcEPSS 1.9%CVE-2018-2446Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (seEPSS 1.7%CVE-2018-2482SAP Mobile Secure Android Application, Mobile-secure.apk Android client, before version 6.60.19942.0, allows an attacker to prevent legitimaEPSS 1.7%CVE-2018-2438The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attackeEPSS 1.7%CVE-2021-41251MEDIUMPossibility to elevate privileges or get unauthorized access to dataEPSS 1.7%CVE-2018-2479SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs,EPSS 1.6%CVE-2018-2502TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that aEPSS 1.6%CVE-2018-2416SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.EPSS 1.6%CVE-2018-2464SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-EPSS 1.6%CVE-2018-2470In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encEPSS 1.6%CVE-2018-2444SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-SiEPSS 1.6%CVE-2018-2505SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts thaEPSS 1.6%CVE-2018-2472SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlleEPSS 1.6%