Medium - CVE-2025-25244 - SAP Business Warehouse (Process Chains) allows...
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain...
Medium - CVE-2025-25245 - SAP BusinessObjects Business Intelligence...
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by...
Low - CVE-2025-26655 - SAP Just In Time(JIT) does not perform...
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a...
Medium - CVE-2025-26656 - OData Service in Manage Purchasing Info Records...
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on...
Medium - CVE-2025-26658 - The Service Layer in SAP Business One, allows...
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access and impersonate other users in the application to perform unauthorized actions. Due to the improper...
Medium - CVE-2025-26659 - SAP NetWeaver Application Server ABAP does not...
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges,...
Medium - CVE-2025-26660 - SAP Fiori applications using the posting...
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an...
High - CVE-2025-26661 - Due to missing authorization check, SAP...
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful...
Low - CVE-2025-27430 - Under certain conditions, an SSRF vulnerability...
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the...
Medium - CVE-2025-27431 - User management functionality in SAP NetWeaver...
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored...