4.3

CVSS3.1

CVE-2024-47581 - Missing Authorization check in SAP HCM (Approve Timesheets version 4)

SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.

πŸ“… Published: Dec. 10, 2024, 12:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-47580 - Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)

An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or …

πŸ“… Published: Dec. 10, 2024, 12:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-47579 - Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the…

πŸ“… Published: Dec. 10, 2024, 12:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-47578 - Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Req…

πŸ“… Published: Dec. 10, 2024, 12:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-47577 - Information Disclosure vulnerability in SAP Commerce Cloud

Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an attacker impersonating as…

πŸ“… Published: Dec. 10, 2024, 12:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-47576 - DLL Hijacking vulnerability in SAP Product Lifecycle Costing

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execut…

πŸ“… Published: Dec. 10, 2024, 12:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-32732 - Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.

πŸ“… Published: Dec. 10, 2024, 12:11 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 6:29 p.m.

6.1

CVSS3.1

CVE-2024-53481 -

A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2025, 8:35 p.m.

9.8

CVSS3.1

CVE-2024-45493 -

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate w…

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-45494 -

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected f…

πŸ“… Published: Dec. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346554
Page 7295 of 34,656
Β« previous page Β» next page
Filters