Vulnerabilidades em SAP SE

778 resultados
Análise Vexday

Com 778 CVEs catalogadas, o portfólio da SAP SE apresenta uma taxa de exploração ativa 1,7 vez acima da média geral do catálogo CISA KEV, indicando que vulnerabilidades nessa plataforma atraem atenção proporcional de agentes de ameaça. O tipo de falha mais recorrente é CWE-119 (erros de manipulação de memória), um vetor historicamente associado a impacto elevado de execução de código. A CVE mais crítica em exploração ativa, CVE-2020-6287, — neste caso CVE-2020-6207 — registra EPSS de 0,9838, sinalizando probabilidade muito alta de exploração observada na prática e justificando priorização imediata de remediação. Além disso, 18 vulnerabilidades possuem PoC pública e 46 são de severidade crítica, ampliando a superfície de risco para organizações que ainda não aplicaram os patches correspondentes.

CVE-2022-41208MEDIUMDue to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to aEPSS 0.4%CVE-2020-6289MEDIUMSAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user iEPSS 0.4%CVE-2022-31597Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/SlovakEPSS 0.4%CVE-2021-21482HIGHSAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to EPSS 0.4%CVE-2019-0402SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leaEPSS 0.4%CVE-2021-42066SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypteEPSS 0.4%CVE-2022-41210MEDIUMSAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for EPSS 0.4%CVE-2022-41186Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from uEPSS 0.4%CVE-2018-2425HIGHUnder certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherEPSS 0.4%CVE-2022-41207MEDIUMSAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use EPSS 0.4%CVE-2022-41185Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received fEPSS 0.4%CVE-2022-41258MEDIUMDue to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious scripEPSS 0.4%CVE-2019-0357The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privilEPSS 0.4%CVE-2019-0256Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwiseEPSS 0.4%CVE-2019-0291Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.EPSS 0.4%CVE-2020-6228MEDIUMSAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain coEPSS 0.4%CVE-2022-41180Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received EPSS 0.4%CVE-2022-39808Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untEPSS 0.4%CVE-2023-40306MEDIUMURL Redirection vulnerability in SAP S/4HANA (Manage Catalog Items and Cross-Catalog search)EPSS 0.4%CVE-2020-6206MEDIUMSAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mEPSS 0.4%