7.7

CVSS3.1

CVE-2025-30014 - Directory Traversal vulnerability in SAP Capital Yield Tax Management

SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they don๏ฟฝt have access to, hence causing a high impact on confidentiality. Integrity and Availability are nโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:14 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-30013 - Code Injection vulnerability in SAP ERP BW Business Content

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended โ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:14 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-27437 - Missing Authorization check in SAP NetWeaver Application Server ABAP (Virus Scan Interface)

A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further aโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2025-27435 - Information Disclosure Vulnerability in SAP Commerce Cloud

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and inteโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-27429 - Code Injection Vulnerability in SAP S/4HANA (Private Cloud or On-Premise)

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating tโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-27428 - Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection)

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentialโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-26657 - Information Disclosure vulnerability in SAP KMC WPC

SAP KMC WPC allows an unauthenticated attacker to remotely retrieve usernames by a simple parameter query which could expose sensitive information causing low impact on confidentiality of the application. This has no effect on integrity and availability.

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-26654 - Potential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request bโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-26653 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications basโ€ฆ

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, โ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:10 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-23186 - Mixed Dynamic RFC Destination vulnerability through Remote Function Call (RFC) in SAP NetWeaver Appโ€ฆ

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromโ€ฆ

๐Ÿ“… Published: April 8, 2025, 7:10 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345165
Page 5572 of 34,517
ยซ previous page ยป next page
Filters