Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2020-6267MEDIUMSome sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only EPSS 0.8%CVE-2020-6251MEDIUMUnder certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access iEPSS 0.8%CVE-2020-6281MEDIUMSAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resultEPSS 0.8%CVE-2019-0275SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, EPSS 0.8%CVE-2020-6181MEDIUMUnder some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_EPSS 0.8%CVE-2020-6260MEDIUMSAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, EPSS 0.8%CVE-2020-6261MEDIUMSAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XMEPSS 0.8%CVE-2020-6222MEDIUMSAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-EPSS 0.8%CVE-2020-6259MEDIUMUnder certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwiseEPSS 0.8%CVE-2022-31595SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalatiEPSS 0.8%CVE-2021-21487MEDIUMSAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privilEPSS 0.8%CVE-2022-35290HIGHUnder certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.EPSS 0.8%CVE-2020-6205MEDIUMSAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7EPSS 0.8%CVE-2022-26103Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which couldEPSS 0.8%CVE-2021-33663MEDIUMSAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.2EPSS 0.8%CVE-2021-33674MEDIUMUnder certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to EPSS 0.8%CVE-2022-41259MEDIUMSAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server EPSS 0.8%CVE-2021-38174MEDIUMWhen a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes EPSS 0.8%CVE-2021-33681MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out ofEPSS 0.8%CVE-2020-6305MEDIUMPI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputEPSS 0.8%