5.4

CVSS3.1

CVE-2025-27431 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unautโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-27430 - Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)

Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentialโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-26661 - Missing Authorization check in SAP NetWeaver (ABAP Class Builder)

Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a highโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-26660 - Broken Access Control in SAP Fiori apps (Posting Library)

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potenโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:36 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-26659 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications basโ€ฆ

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the mโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:36 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-26658 - Broken Authentication in SAP Business One (Service Layer)

The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper session management, the attackers can elevate themselves to higher privilege and can read, modify and/oโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-26656 - Missing Authorization check in S/4HANA (Manage Purchasing Info Records)

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.

๐Ÿ“… Published: March 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-26655 - Missing Authorization check in SAP JIT(Outbound)

SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.

๐Ÿ“… Published: March 11, 2025, 12:35 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-25245 - Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Webโ€ฆ

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:34 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2025, 6:41 p.m.

5.7

CVSS3.1

CVE-2025-25244 - Missing Authorization Check in SAP Business Warehouse (Process Chains)

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loadโ€ฆ

๐Ÿ“… Published: March 11, 2025, 12:34 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6396 of 34,919
ยซ previous page ยป next page
Filters