5

CVSS3.1

CVE-2026-27688 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially e…

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

5.8

CVSS3.1

CVE-2026-27687 - Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal

Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

5.9

CVSS3.1

CVE-2026-27686 - Missing Authorization check in SAP Business Warehouse (Service API)

Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request process…

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

9.1

CVSS3.1

CVE-2026-27685 - Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 4 a.m.

6.4

CVSS3.1

CVE-2026-27684 - SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification)

SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As …

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

5

CVSS3.1

CVE-2026-24317 - DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's c…

πŸ“… Published: March 10, 2026, 12:18 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

6.4

CVSS3.1

CVE-2026-24316 - Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with po…

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

5

CVSS3.1

CVE-2026-24313 - Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

5.6

CVSS3.1

CVE-2026-24311 - Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0

The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could …

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

3.5

CVSS3.1

CVE-2026-24310 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality …

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.
Total resulsts: 349182
Page 1228 of 34,919
Β« previous page Β» next page
Filters