Home/Product/sap erp
Product

sap erp

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24323
all versions
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are
6.1MEDIUM
CVE-2026-0505
all versions
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validate
6.1MEDIUM
CVE-2025-29390
all versions
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
8.8HIGH
CVE-2024-42565
all versions
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/dele
9.8CRITICAL
CVE-2024-42564
all versions
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/de
7.6HIGH
CVE-2024-42563
<= 2018-03-02
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTM
9.8CRITICAL
CVE-2022-30076
all versions
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s
5.3MEDIUM
CVE-2023-26762
all versions
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.
8.8HIGH
CVE-2023-26760
all versions
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulne
7.5HIGH
CVE-2023-26759
all versions
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService compo
8.8HIGH
CVE-2023-26758
all versions
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.
7.5HIGH
CVE-2022-3944
all versions
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uplo
6.3MEDIUM
CVE-2020-6316
all versions
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS report
4.3MEDIUM
CVE-2020-8967
< 11.2
There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO
10.0CRITICAL
CVE-2020-6212
all versions
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730
5.4MEDIUM
CVE-2020-6199
all versions
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HAN
5.4MEDIUM
CVE-2020-6188
all versions
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730)
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin