4.3
CVE-2025-31333 - Odata meta-data tampering in SAP S4CORE entity
SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.
6.6
CVE-2025-31332 - Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform
Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence leading to a high impact on integrity and availability. However, this vulnerabiβ¦
4.3
CVE-2025-31331 - Authorization Bypass vulnerability in SAP NetWeaver
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorizatiβ¦
9.9
CVE-2025-31330 - Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform)
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions asβ¦
4.4
CVE-2025-30017 - Missing Authorization check in SAP Solution Manager
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.
9.8
CVE-2025-30016 - Authentication Bypass Vulnerability in SAP Financial Consolidation
SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.
4.1
CVE-2025-30015 - Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impactβ¦
7.7
CVE-2025-30014 - Directory Traversal vulnerability in SAP Capital Yield Tax Management
SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could allow an attacker with low privileges to read files from directory which they donοΏ½t have access to, hence causing a high impact on confidentiality. Integrity and Availability are nβ¦
6.7
CVE-2025-30013 - Code Injection vulnerability in SAP ERP BW Business Content
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended β¦
4.3
CVE-2025-27437 - Missing Authorization check in SAP NetWeaver Application Server ABAP (Virus Scan Interface)
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further aβ¦