Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2022-27654When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versiEPSS 1.1%CVE-2019-0280SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not peEPSS 1.1%CVE-2020-6282MEDIUMSAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP servicEPSS 1.1%CVE-2022-29618Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, aEPSS 1.1%CVE-2019-0331Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to aEPSS 1.1%CVE-2019-0338During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not propEPSS 1.1%CVE-2019-0383Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0,EPSS 1.1%CVE-2019-0279ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versioEPSS 1.1%CVE-2019-0301Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST IEPSS 1.1%CVE-2020-6225CRITICALSAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does EPSS 1.1%CVE-2021-38181SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prEPSS 1.1%CVE-2020-6285HIGHSAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an atEPSS 1.1%CVE-2021-33672CRITICALDue to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chaEPSS 1.1%CVE-2019-0405SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of useEPSS 1.1%CVE-2019-0404SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information DiscEPSS 1.1%CVE-2021-33698CRITICALSAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the prEPSS 1.1%CVE-2020-6365MEDIUMSAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirectEPSS 1.1%CVE-2021-42064If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP CEPSS 1.1%CVE-2020-6224MEDIUMSAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges toEPSS 1.1%CVE-2021-37535CRITICALSAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authEPSS 1.1%