Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2020-6183MEDIUMSAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the EPSS 0.7%CVE-2019-0340The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML ValidatiEPSS 0.7%CVE-2019-0348SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, eEPSS 0.7%CVE-2019-0334When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to storeEPSS 0.7%CVE-2020-6258MEDIUMSAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to viEPSS 0.7%CVE-2020-6188MEDIUMVAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP SEPSS 0.7%CVE-2020-6283MEDIUMSAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the lauEPSS 0.7%CVE-2020-6268MEDIUMStatutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versionEPSS 0.7%CVE-2022-39013Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker tEPSS 0.7%CVE-2020-6376MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sEPSS 0.7%CVE-2020-6375MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from uEPSS 0.7%CVE-2021-21491MEDIUMSAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow EPSS 0.7%CVE-2022-41193Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusEPSS 0.7%CVE-2022-29612SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22EPSS 0.7%CVE-2022-35169SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decryptEPSS 0.7%CVE-2021-33667MEDIUMUnder certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source EPSS 0.7%CVE-2020-6288MEDIUMSAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to uploadEPSS 0.7%CVE-2022-32238When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise ViewEPSS 0.7%CVE-2022-32242When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, theEPSS 0.7%CVE-2020-6211MEDIUMSAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious sitEPSS 0.7%