VendorsSAPbusiness_planning_and_consolidation810
Vulnerabilities

SAP Business Planning 810

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-0016
SQL Injection vulnerability in SAP Business Planning and Consolidation MS
Published 2023-01-10 · Modified
9.9EPSS 0.006
CVE-2022-41268
In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.
Published 2022-12-13 · Modified
8.5EPSS 0.006
CVE-2020-6368
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Published 2020-10-15 · Modified
5.4EPSS 0.006