Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Business One (Service Layer) | B1_ON_HANA 10.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-27434 | 8.8 HIGH | Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) |
| CVE-2025-26661 | 8.8 HIGH | Missing Authorization check in SAP NetWeaver (ABAP Class Builder) |
| CVE-2025-25242 | 6.1 MEDIUM | Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP |
| CVE-2025-26659 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applica |
| CVE-2025-25244 | 5.7 MEDIUM | Missing Authorization Check in SAP Business Warehouse (Process Chains) |
| CVE-2025-25245 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2025-27431 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java |
| CVE-2025-23194 | 5.3 MEDIUM | Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) |
| CVE-2025-0071 | 4.9 MEDIUM | Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Mana |
| CVE-2025-0062 | 4.7 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2025-27436 | 4.3 MEDIUM | Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) |
| CVE-2025-27433 | 4.3 MEDIUM | Broken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements) |
| CVE-2025-26660 | 4.3 MEDIUM | Broken Access Control in SAP Fiori apps (Posting Library) |
| CVE-2025-26656 | 4.3 MEDIUM | Missing Authorization check in S/4HANA (Manage Purchasing Info Records) |
| CVE-2025-23188 | 4.3 MEDIUM | Missing Authorization check in SAP S/4HANA (RBD) |
| CVE-2025-23185 | 4.1 MEDIUM | Information Disclosure in SAP Business Objects Business Intelligence Platform |
| CVE-2025-27430 | 3.5 LOW | Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center) |
| CVE-2025-26655 | 3.1 LOW | Missing Authorization check in SAP JIT(Outbound) |
| CVE-2025-27432 | 2.4 LOW | Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit) |
No comments yet