VendorsSAPbusiness_planning_and_consolidation750
Vulnerabilities

SAP Business Planning 750

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-41268
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Published 2022-12-13 · Modified
8.5EPSS 0.006
CVE-2020-6368
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Published 2020-10-15 · Modified
5.4EPSS 0.006
CVE-2023-31407
Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation
Published 2023-05-09 · Modified
5.4EPSS 0.003