Filtered by vendor Sap Subscriptions
Total 1502 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-42373 1 Sap 1 Student Life Cycle Management 2024-09-12 4.3 Medium
SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.
CVE-2024-41732 1 Sap 1 Netweaver Application Server Abap 2024-09-11 4.7 Medium
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.