6.6
CVE-2024-12083 - Path Traversal Vulnerabilities in NJ/NX-series Machine Automation Controllers
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
5.5
CVE-2024-12298 - Vulnerability Report on Improper Restriction of XML External Entity Reference in NB-Designer
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.
9.9
CVE-2025-0070 - Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This โฆ
7.8
CVE-2025-0069 - DLL Hijacking vulnerability in SAPSetup
Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user๏ฟฝs Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a companyโฆ
4.3
CVE-2025-0068 - Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
6.3
CVE-2025-0067 - Missing Authorization check in SAP NetWeaver Application Server Java
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentialityโฆ
9.9
CVE-2025-0066 - Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Commuโฆ
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application
8.8
CVE-2025-0063 - SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and avaโฆ
8.7
CVE-2025-0061 - Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.
6.5
CVE-2025-0060 - Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged usโฆ