VendorsSAPgraphical_user_interfaceall versions
Vulnerabilities

SAP Graphical User Interface

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-49580
Information disclosure in SAP GUI for Windows and SAP GUI for Java
Published 2023-12-12 · Modified
7.3EPSS 0.005
CVE-2011-5154
Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.
Published 2012-09-06 · Modified
6.9EPSS 0.004
CVE-2021-21448
SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memory. Under certain conditions the attacker can access information which would otherwise be restricted. The exploit can only be executed locally on the client PC and not via Network and the attacker needs at least user authorization of the Operating System user of the victim.
Published 2021-01-12 · Modified
6.5EPSS 0.003