Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2021-27640MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crEPSS 0.6%CVE-2021-33659MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crEPSS 0.6%CVE-2021-27638MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in craEPSS 0.6%CVE-2021-33660MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crEPSS 0.6%CVE-2021-27641MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crEPSS 0.6%CVE-2021-21492MEDIUMSAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logEPSS 0.6%CVE-2020-6273MEDIUMSAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticatEPSS 0.6%CVE-2022-27656The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inEPSS 0.6%CVE-2021-33695MEDIUMPotentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.EPSS 0.6%CVE-2022-39804Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Part (.sldprt, CoreCadTranslator.exe) file received frEPSS 0.6%CVE-2022-39803Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file receiveEPSS 0.6%CVE-2019-0367SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authentEPSS 0.5%CVE-2022-35228SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricteEPSS 0.5%CVE-2022-35226SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it wilEPSS 0.5%CVE-2021-33683MEDIUMSAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22EPSS 0.5%CVE-2021-42070When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9EPSS 0.5%CVE-2021-42068When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the applicEPSS 0.5%CVE-2021-33689LOWWhen user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version EPSS 0.5%CVE-2021-33666MEDIUMWhen SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, coulEPSS 0.5%CVE-2021-33693MEDIUMSAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that coulEPSS 0.5%