Home/Product/sap s4core
Product

sap s4core

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24323
all versions
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are
6.1MEDIUM
CVE-2026-23688
all versions
SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in
4.3MEDIUM
CVE-2026-0505
all versions
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validate
6.1MEDIUM
CVE-2024-37172
all versions
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, result
5.4MEDIUM
CVE-2024-39592
all versions
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
7.7HIGH
CVE-2023-40625
all versions
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks fo
5.4MEDIUM
CVE-2023-35870
all versions
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an att
6.3MEDIUM
CVE-2023-32112
all versions
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 60
2.8LOW
CVE-2023-29110
all versions
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C,
3.7LOW
CVE-2023-29109
all versions
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA
4.4MEDIUM
CVE-2021-33701
all versions
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 7
9.1CRITICAL
CVE-2018-2484
all versions
SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.
8.8HIGH
CVE-2018-2419
all versions
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) doe
3.7LOW
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin