6.1

CVSS3.1

CVE-2025-25242 - Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP

SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.

πŸ“… Published: March 11, 2025, 12:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-23194 - Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.

πŸ“… Published: March 11, 2025, 12:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-23188 - Missing Authorization check in SAP S/4HANA (RBD)

An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.

πŸ“… Published: March 11, 2025, 12:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2025-23185 - Information Disclosure in SAP Business Objects Business Intelligence Platform

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they coul…

πŸ“… Published: March 11, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-0071 - Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager

SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact …

πŸ“… Published: March 11, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-0062 - Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web…

SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful exploitation, an attacker could cause limited impact …

πŸ“… Published: March 11, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2025-25928 -

A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In this case, an attacker could elevate a low-privileged account to an administrative role by leveraging the CSRF vulnera…

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:14 p.m.

8.8

CVSS3.1

CVE-2025-27912 -

An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authentication is in use and a user visits a compromised/malicious site, or (2) when username/password or Active Directory authentication is in use and a…

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2021-37787 -

The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE module

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 7:28 p.m.

6.8

CVSS3.1

CVE-2025-25927 -

A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 7:15 p.m.
Total resulsts: 349182
Page 6397 of 34,919
Β« previous page Β» next page
Filters