Vulnerabilidades em SAP

159 resultados
Análise Vexday

Com 159 CVEs catalogadas e nenhuma atualmente registrada no catálogo KEV da CISA, o perfil de exploração ativa do SAP situa-se abaixo da média geral do catálogo, o que representa um indicador favorável no curto prazo, mas não elimina atenção recomendada às 16 vulnerabilidades de severidade crítica. A falha mais comum é CWE-79 (Cross-Site Scripting), sugerindo que problemas de sanitização de entrada em interfaces web constituem o padrão predominante na superfície de ataque. A CVE mais perigosa no momento, CVE-2023-29186, apresenta EPSS de 0,2304 — o maior valor observado no conjunto —, indicando probabilidade não desprezível de exploração mesmo sem confirmação ativa no KEV. A existência de pelo menos um PoC público reforça a necessidade de priorizar a remediação das vulnerabilidades críticas antes que o cenário de exploração se altere.

CVE-2022-41264HIGHDue to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 7EPSS 0.9%CVE-2022-41267CRITICALSAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on BusinEPSS 0.8%CVE-2018-2488It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori EPSS 0.8%CVE-2018-2491When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If thisEPSS 0.8%CVE-2018-2460SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to doEPSS 0.8%CVE-2018-2494Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAPEPSS 0.8%CVE-2023-27497CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)EPSS 0.8%CVE-2018-2490The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store aEPSS 0.7%CVE-2023-0022CRITICALCode Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analysis edition for OLAP)EPSS 0.7%CVE-2018-2442In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the userEPSS 0.7%CVE-2023-0014CRITICALCapture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.7%CVE-2022-31596MEDIUMUnder certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjEPSS 0.7%CVE-2018-2474SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintEPSS 0.7%CVE-2023-27897MEDIUMCode Injection vulnerability in SAP CRMEPSS 0.7%CVE-2023-27894MEDIUMSensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platformEPSS 0.6%CVE-2023-0016CRITICALSQL Injection vulnerability in SAP Business Planning and Consolidation MSEPSS 0.6%CVE-2023-28763MEDIUMDenial of Service in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-25618MEDIUMDenial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2023-27270MEDIUMDenial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.6%CVE-2018-2434A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which mighEPSS 0.6%