5.4
CVE-2025-27431 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unautโฆ
3.5
CVE-2025-27430 - Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentialโฆ
8.8
CVE-2025-26661 - Missing Authorization check in SAP NetWeaver (ABAP Class Builder)
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a highโฆ
4.3
CVE-2025-26660 - Broken Access Control in SAP Fiori apps (Posting Library)
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potenโฆ
6.1
CVE-2025-26659 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications basโฆ
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the mโฆ
6.8
CVE-2025-26658 - Broken Authentication in SAP Business One (Service Layer)
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/oโฆ
4.3
CVE-2025-26656 - Missing Authorization check in S/4HANA (Manage Purchasing Info Records)
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
3.1
CVE-2025-26655 - Missing Authorization check in SAP JIT(Outbound)
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
5.4
CVE-2025-25245 - Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Webโฆ
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limโฆ
5.7
CVE-2025-25244 - Missing Authorization Check in SAP Business Warehouse (Process Chains)
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loadโฆ