5.4

CVSS3.1

CVE-2025-42896 - Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URLs, resulting in low impact to confidentiality and integrity,โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:15 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

5.5

CVSS3.1

CVE-2025-42891 - Missing Authorization check in SAP Enterprise Search for ABAP

Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on applicโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:15 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

9.9

CVSS3.1

CVE-2025-42880 - Code Injection vulnerability in SAP Solution Manager

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:15 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

8.2

CVSS3.1

CVE-2025-42878 - Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)

SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability aโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

7.5

CVSS3.1

CVE-2025-42877 - Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Conteโ€ฆ

SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

7.1

CVSS3.1

CVE-2025-42876 - Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could โ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

6.6

CVSS3.1

CVE-2025-42875 - Missing Authentication check in SAP NetWeaver Internet Communication Framework

The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the appliโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

7.9

CVSS3.1

CVE-2025-42874 - Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)

SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to sโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

5.9

CVSS3.1

CVE-2025-42873 - Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:14 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

6.1

CVSS3.1

CVE-2025-42872 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users๏ฟฝ browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a resultโ€ฆ

๐Ÿ“… Published: Dec. 9, 2025, 2:13 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.
Total resulsts: 343970
Page 2227 of 34,397
ยซ previous page ยป next page
Filters