Vulnerabilidades en SAP SE

778 resultados
Análisis Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2022-41208MEDIUMDue to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to aEPSS 0.4%CVE-2022-31597—Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/SlovakEPSS 0.4%CVE-2020-6289MEDIUMSAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user iEPSS 0.4%CVE-2021-21482HIGHSAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to EPSS 0.4%CVE-2019-0402—SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leaEPSS 0.4%CVE-2021-42066—SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypteEPSS 0.4%CVE-2022-41210MEDIUMSAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for EPSS 0.4%CVE-2022-41186—Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from uEPSS 0.4%CVE-2018-2425HIGHUnder certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherEPSS 0.4%CVE-2022-41207MEDIUMSAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use EPSS 0.4%CVE-2022-41258MEDIUMDue to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious scripEPSS 0.4%CVE-2022-41185—Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received fEPSS 0.4%CVE-2019-0357—The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privilEPSS 0.4%CVE-2019-0291—Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.EPSS 0.4%CVE-2019-0256—Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwiseEPSS 0.4%CVE-2020-6228MEDIUMSAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain coEPSS 0.4%CVE-2022-39808—Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%CVE-2022-41180—Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2023-40306MEDIUMURL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)EPSS 0.4%CVE-2020-6206MEDIUMSAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mEPSS 0.4%