VendorsSAPbusiness_planning_and_consolidationall versions
Vulnerabilities

SAP Business Planning

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-0016
SQL Injection vulnerability in SAP Business Planning and Consolidation MS
Published 2023-01-10 · Modified
9.9EPSS 0.006
CVE-2022-41268
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Published 2022-12-13 · Modified
8.5EPSS 0.006
CVE-2017-16349
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue authenticated HTTP requests to trigger this vulnerability.
Published 2018-08-02 · Modified
8.1EPSS 0.012
CVE-2020-6368
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Published 2020-10-15 · Modified
5.4EPSS 0.006
CVE-2023-23851
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.
Published 2023-02-14 · Modified
5.4EPSS 0.003
CVE-2023-31407
Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
Published 2023-05-09 · Modified
5.4EPSS 0.003