4.3

CVSS3.1

CVE-2026-23688 - Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 5:18 p.m.

8.8

CVSS3.1

CVE-2026-23687 - XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive u…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 11, 2026, 4:56 a.m.

3.4

CVSS3.1

CVE-2026-23686 - CRLF Injection vulnerability in SAP NetWeaver Application Server Java

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configu…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 5:19 p.m.

4.4

CVSS3.1

CVE-2026-23685 - Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic executio…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 5:19 p.m.

5.9

CVSS3.1

CVE-2026-23684 - Race condition vulnerability in SAP Commerce Cloud

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confide…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 5:19 p.m.

8.6

CVSS4.0

CVE-2026-2260 - D-Link DCS-931L setSysAdmin os command injection

A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argument AdminID results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerabil…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 6:36 p.m.

4.3

CVSS3.1

CVE-2026-23681 - Missing Authorization check in a function module in SAP Support Tools Plug-In

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subseque…

📅 Published: Feb. 10, 2026, 3:02 a.m. 🔄 Last Modified: Feb. 10, 2026, 6:37 p.m.

9.6

CVSS3.1

CVE-2026-0509 - Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidenti…

📅 Published: Feb. 10, 2026, 3:01 a.m. 🔄 Last Modified: Feb. 10, 2026, 4:27 p.m.

7.3

CVSS3.1

CVE-2026-0508 - Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Upon successful exploitation, the victim may click on this malicious URL, resulting in an unvalidated redirect to the attacker-controlled doma…

📅 Published: Feb. 10, 2026, 3:01 a.m. 🔄 Last Modified: Feb. 11, 2026, 4:56 a.m.

6.1

CVSS3.1

CVE-2026-0505 - Multiple vulnerabilities in BSP Applications of SAP Document Management System

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availabil…

📅 Published: Feb. 10, 2026, 3:01 a.m. 🔄 Last Modified: Feb. 10, 2026, 4:28 p.m.
Total resulsts: 332122
Page 32 of 33,213
« previous page » next page
Filters