Skip to main content

Vendor/product archive

sap / cloud_connector CVEs

Beta · best-effort

8 CVEs tagged to sap / cloud_connector3 Critical, 2 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2024-25642

Published Feb 13, 2024

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authenticatio…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49578

Published Dec 12, 2023

SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-33695

Published Sep 15, 2021

Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33694

Published Sep 15, 2021

SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33693

Published Sep 15, 2021

SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execut…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33692

Published Sep 15, 2021

SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0247

Published Jan 8, 2019

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the applic…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-0246

Published Jan 8, 2019

SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1