6.1

CVSS3.1

CVE-2026-0514 - Cross-Site Scripting (XSS) vulnerability in SAP Business Connector

Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to acc…

πŸ“… Published: Jan. 13, 2026, 1:16 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.

4.7

CVSS3.1

CVE-2026-0513 - Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)

Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. C…

πŸ“… Published: Jan. 13, 2026, 1:15 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

8.1

CVSS3.1

CVE-2026-0511 - Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation)

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.

πŸ“… Published: Jan. 13, 2026, 1:15 a.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

3

CVSS3.1

CVE-2026-0510 - Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping

The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially …

πŸ“… Published: Jan. 13, 2026, 1:15 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

8.4

CVSS3.1

CVE-2026-0507 - OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables exec…

πŸ“… Published: Jan. 13, 2026, 1:15 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

8.1

CVSS3.1

CVE-2026-0506 - Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs …

πŸ“… Published: Jan. 13, 2026, 1:14 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

3.8

CVSS3.1

CVE-2026-0504 - Insufficient Input Handling in JNDI Operations of SAP Identity Management

Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification o…

πŸ“… Published: Jan. 13, 2026, 1:14 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

6.4

CVSS3.1

CVE-2026-0503 - Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management)

Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can…

πŸ“… Published: Jan. 13, 2026, 1:14 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

9.9

CVSS3.1

CVE-2026-0501 - SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials οΏ½ General Ledge…

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of…

πŸ“… Published: Jan. 13, 2026, 1:14 a.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

9.6

CVSS3.1

CVE-2026-0500 - Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation)

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope…

πŸ“… Published: Jan. 13, 2026, 1:13 a.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.
Total resulsts: 349182
Page 2175 of 34,919
Β« previous page Β» next page
Filters