Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver Enterprise Portal (OBN component) | EP-RUNTIME 7.50 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-27434 | 8.8 HIGH | Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) |
| CVE-2025-26661 | 8.8 HIGH | Missing Authorization check in SAP NetWeaver (ABAP Class Builder) |
| CVE-2025-26658 | 6.8 MEDIUM | Broken Authentication in SAP Business One (Service Layer) |
| CVE-2025-25242 | 6.1 MEDIUM | Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP |
| CVE-2025-26659 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applica |
| CVE-2025-25244 | 5.7 MEDIUM | Missing Authorization Check in SAP Business Warehouse (Process Chains) |
| CVE-2025-27431 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java |
| CVE-2025-25245 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2025-0071 | 4.9 MEDIUM | Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Mana |
| CVE-2025-0062 | 4.7 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2025-26656 | 4.3 MEDIUM | Missing Authorization check in S/4HANA (Manage Purchasing Info Records) |
| CVE-2025-26660 | 4.3 MEDIUM | Broken Access Control in SAP Fiori apps (Posting Library) |
| CVE-2025-23188 | 4.3 MEDIUM | Missing Authorization check in SAP S/4HANA (RBD) |
| CVE-2025-27433 | 4.3 MEDIUM | Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) |
| CVE-2025-27436 | 4.3 MEDIUM | Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) |
| CVE-2025-23185 | 4.1 MEDIUM | Information Disclosure in SAP Business Objects Business Intelligence Platform |
| CVE-2025-27430 | 3.5 LOW | Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) |
| CVE-2025-26655 | 3.1 LOW | Missing Authorization check in SAP JIT(Outbound) |
| CVE-2025-27432 | 2.4 LOW | Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit) |
No comments yet