9.1

CVSS3.1

CVE-2025-42999 - Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

📅 Published: May 13, 2025, 12:17 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

6.6

CVSS3.1

CVE-2025-42997 - Information Disclosure vulnerability in SAP Gateway Client

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on c…

📅 Published: May 13, 2025, 12:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-31329 - Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user …

📅 Published: May 13, 2025, 12:16 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-30018 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the applicat…

📅 Published: May 13, 2025, 12:16 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:43 p.m.

10

CVSS3.1

CVE-2025-30012 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which will result in deserial…

📅 Published: May 13, 2025, 12:14 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:52 p.m.

5.3

CVSS3.1

CVE-2025-30011 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected…

📅 Published: May 13, 2025, 12:13 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:55 p.m.

6.1

CVSS3.1

CVE-2025-30010 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successfu…

📅 Published: May 13, 2025, 12:13 a.m. 🔄 Last Modified: Oct. 23, 2025, 4:57 p.m.

6.1

CVSS3.1

CVE-2025-30009 - Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integ…

📅 Published: May 13, 2025, 12:12 a.m. 🔄 Last Modified: Oct. 23, 2025, 5 p.m.

4.4

CVSS3.1

CVE-2025-26662 - Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This p…

📅 Published: May 13, 2025, 12:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-56526 -

An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

📅 Published: May 13, 2025, midnight 🔄 Last Modified: Jan. 29, 2026, 8:47 p.m.
Total resulsts: 349182
Page 5449 of 34,919
« previous page » next page
Filters