Filtered by vendor Sap
Subscriptions
Total
1723 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76968 | 1 Sap | 3 Content Server, Internet Communication Manager, Web Dispatcher | 2026-09-08 | 6.5 Medium |
| SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability. | ||||
| CVE-2026-76967 | 1 Sap | 1 Netweaver Business Client | 2026-09-08 | 7.8 High |
| SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. | ||||
| CVE-2026-76971 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2026-09-08 | 6.5 Medium |
| Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful exploitation could result in a low impact on the confidentiality, integrity, and availability of the application. | ||||
| CVE-2026-66774 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 3.7 Low |
| SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-66760 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 6.4 Medium |
| SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and a low impact on confidentiality and availability. | ||||
| CVE-2026-58238 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.9 Medium |
| SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-58230 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 7 High |
| SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability. | ||||
| CVE-2026-27690 | 2 Sap, Sap Se | 2 Approuter, Sap Approuter | 2026-09-08 | 9.1 Critical |
| Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability. | ||||
| CVE-2026-66776 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.9 Medium |
| SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-66778 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.3 Medium |
| SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. | ||||
| CVE-2026-44745 | 2 Sap, Sap Se | 2 Approuter, Sap Approuter | 2026-09-08 | 8.1 High |
| SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application. | ||||
| CVE-2026-58237 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.9 Medium |
| WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-58239 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 3.7 Low |
| SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability. | ||||
| CVE-2026-66761 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 4.3 Medium |
| SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-66775 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 4.3 Medium |
| SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability. | ||||
| CVE-2026-66777 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.9 Medium |
| SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-44758 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2026-08-11 | 9.1 Critical |
| SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application. | ||||
| CVE-2026-44763 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2026-08-11 | 7.6 High |
| SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability. | ||||
| CVE-2026-44764 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2026-08-11 | 7.3 High |
| Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resulting in a limited impact on the confidentiality, integrity, and availability of the affected system. | ||||
| CVE-2026-44765 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2026-08-11 | 7.3 High |
| Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability. | ||||