NA - CVE-2024-45286 - Due to lack of proper authorization checks when...
Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to...
NA - CVE-2024-0067 - Marinus Pfund, member of the AXIS OS Bug Bounty...
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system...
NA - CVE-2024-21528 - All versions of the package node-gettext are...
All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.
NA - CVE-2024-44117 - The RFC enabled function module allows a low...
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on...
NA - CVE-2024-44120 - SAP NetWeaver Enterprise Portal is vulnerable...
SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and...
NA - CVE-2024-44121 - Under certain conditions Statutory Reports in...
Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose...
NA - CVE-2024-45279 - Due to insufficient input validation, CRM...
Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a...
NA - CVE-2024-45280 - Due to insufficient encoding of user-controlled...
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and...
NA - CVE-2024-45281 - SAP BusinessObjects Business Intelligence...
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken....
NA - CVE-2024-45283 - SAP NetWeaver AS for Java allows an authorized...
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful...