6.1
CVE-2025-42962 - Cross-Site Scripting (XSS) vulnerability in SAP Business Warehouse (Business Explorer Web 3.5 loadi…
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is n…
4.9
CVE-2025-42961 - Missing Authorization check in SAP NetWeaver Application Server for ABAP
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized readin…
4.3
CVE-2025-42960 - Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA BEx Tools
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality …
8.1
CVE-2025-42959 - Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation co…
2.7
CVE-2025-42954 - Denial of service (DOS) in SAP NetWeaver Business Warehouse (CCAW application)
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on avail…
8.1
CVE-2025-42953 - Missing Authorization check in SAP NetWeaver Application Server for ABAP
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.
7.7
CVE-2025-42952 - Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This …
4.1
CVE-2025-31326 - HTML Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligenc…
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. This could lead to unintended redirects or manipulation of application behavior, such as redire…
5.3
CVE-2025-7154 - TOTOLINK N200RE cstecgi.cgi sub_41A0F8 os command injection
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack m…
5.1
CVE-2025-7153 - CodeAstro Simple Hospital Management System POST Parameter doctor.html cross site scripting
A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor.html of the component POST Parameter Handler. The manipulation of the argument First Name/Last name/Address leads to…