SAP
SAP Cloud Connector: vulnerabilidades y CVE
SAP Cloud Connector tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-42955 | Baja (3.5) | 0.46% | — | 12 ago 2025 | Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful… |
| CVE-2024-25642 | Alta (7.4) | 0.54% | — | 13 feb 2024 | Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the… |
| CVE-2023-49578 | Baja (3.5) | 0.27% | — | 12 dic 2023 | SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no… |
| CVE-2021-33695 | Crítica (9.1) | 0.56% | — | 15 sept 2021 | Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate. |
| CVE-2021-33694 | Media (4.8) | 0.46% | — | 15 sept 2021 | SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed,… |
| CVE-2021-33693 | Media (6.8) | 0.54% | — | 15 sept 2021 | SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution. |
| CVE-2021-33692 | Alta (7.5) | 1.2% | — | 15 sept 2021 | SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted… |
| CVE-2019-0247 | Crítica (9.8) | 1.3% | — | 8 ene 2019 | SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
| CVE-2019-0246 | Crítica (9.8) | 2.7% | — | 8 ene 2019 | SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. |
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29