Known vulnerabilities in SAP S/4HANA - page 2

Vendor: SAP
Software: SAP S/4HANA
Software CPE: cpe:2.3:o:sap:sap_s_4hana:*:*:*:*:*:*:*:*
Total vulnerabilities: 39
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SAP S/4HANA SAP S/4HANA is affected by 39 known vulnerabilities: 1 high, 17 medium, 21 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU109028 - Missing Authorization
CVE-2025-43008
CWE-862 Low
No
No
- 13.05.2025 SB2025051330
#VU109027 - Exposure of sensitive information to an unauthorized actor
CVE-2025-43003
CWE-200 Low
No
No
- 13.05.2025 SB2025051330
#VU107145 - Server-Side Request Forgery (SSRF)
CVE-2025-27430
CWE-918 Medium
No
No
- 08.04.2025 SB2025040827
#VU107144 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-27429
CWE-94 Medium
No
No
- 08.04.2025 SB2025040826
#VU105507 - Missing Authorization
CVE-2025-26656
CWE-862 Low
No
No
- 11.03.2025 SB2025031136
#VU105506 - Missing Authorization
CVE-2025-23188
CWE-862 Low
No
No
- 11.03.2025 SB2025031136
#VU105505 - Improper Access Control
CVE-2025-27436
CWE-284 Low
No
No
- 11.03.2025 SB2025031136
#VU105504 - Improper Access Control
CVE-2025-27433
CWE-284 Low
No
No
- 11.03.2025 SB2025031136
#VU98139 - Improper input validation
CVE-2024-45282
CWE-20 Low
No
No
- 08.10.2024 SB2024100837
#VU96985 - Exposure of sensitive information to an unauthorized actor
CVE-2024-44121
CWE-200 Low
No
No
- 10.09.2024 SB2024091017
#VU96972 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-42378
CWE-79 Low
No
No
- 10.09.2024 SB2024091011
#VU82116 - Exposure of sensitive information to an unauthorized actor
CVE-2023-42475
CWE-200 Low
No
No
- 17.10.2023 SB2023101767
#VU82047 - Missing Authorization
CVE-2023-42473
CWE-862 Medium
No
No
- 16.10.2023 SB2023101626
#VU81062 - Improper Access Control
CVE-2023-41368
CWE-284 Low
No
No
- 22.09.2023 SB2023092229
#VU81061 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-41369
CWE-835 Low
No
No
- 22.09.2023 SB2023092229
#VU78732 - Improper Access Control
CVE-2023-35870
CWE-284 Low
No
No
- 27.07.2023 SB2023072758
#VU78688 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-36922
CWE-78 Medium
No
No
- 26.07.2023 SB2023072754
#VU78649 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22542
CWE-200 Low
No
No
- 25.07.2023 SB2023072750
#VU55832 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2021-33701
CWE-89 Low
No
No
- 13.08.2021 SB2021081306


Showing elements 21 - 40 out of 39