Vulnerabilities in SAP SE

778 results
Vexday analysis

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2022-41214HIGHDue to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges EPSS 0.8%CVE-2020-6302MEDIUMSAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. AEPSS 0.8%CVE-2020-6270MEDIUMSAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authoEPSS 0.8%CVE-2021-44233—SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated userEPSS 0.8%CVE-2022-24398—Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to accessEPSS 0.8%CVE-2019-0303—SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting EPSS 0.8%CVE-2020-6213MEDIUMSAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754,EPSS 0.8%CVE-2020-6201MEDIUMThe SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to whicEPSS 0.8%CVE-2019-0311—Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode uEPSS 0.8%CVE-2021-33686MEDIUMUnder certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive informaEPSS 0.8%CVE-2021-38179—Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contentsEPSS 0.8%CVE-2020-6209HIGHSAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to adminEPSS 0.8%CVE-2021-27604HIGHIn order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise ServiEPSS 0.8%CVE-2022-22541—SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see EPSS 0.8%CVE-2019-0325—SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll data of employees in a EPSS 0.8%CVE-2022-29611—SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resultiEPSS 0.8%CVE-2020-6269MEDIUMUnder certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which woEPSS 0.8%CVE-2019-0314—SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessEPSS 0.8%CVE-2021-33675MEDIUMUnder certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to EPSS 0.8%CVE-2021-21467MEDIUMSAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalatioEPSS 0.8%