Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2020-6302MEDIUMSAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. AEPSS 0.8%CVE-2020-6270MEDIUMSAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authoEPSS 0.8%CVE-2021-44233SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated userEPSS 0.8%CVE-2022-24398Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to accessEPSS 0.8%CVE-2019-0311Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode uEPSS 0.8%CVE-2019-0303SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting EPSS 0.8%CVE-2020-6201MEDIUMThe SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to whicEPSS 0.8%CVE-2020-6213MEDIUMSAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754,EPSS 0.8%CVE-2022-41214HIGHDue to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges EPSS 0.8%CVE-2021-38179Debug function of Admin UI of SAP Business One Integration is enabled by default. This allows Admin User to see the captured packet contentsEPSS 0.8%CVE-2021-33686MEDIUMUnder certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive informaEPSS 0.8%CVE-2020-6209HIGHSAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to adminEPSS 0.8%CVE-2022-22541SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see EPSS 0.8%CVE-2019-0325SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll data of employees in a EPSS 0.8%CVE-2021-27604HIGHIn order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise ServiEPSS 0.8%CVE-2022-29611SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resultiEPSS 0.8%CVE-2020-6269MEDIUMUnder certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which woEPSS 0.8%CVE-2019-0314SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessEPSS 0.8%CVE-2021-33675MEDIUMUnder certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to EPSS 0.8%CVE-2021-21467MEDIUMSAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalatioEPSS 0.8%