« Volver al listado

SAP

SAP Cloud Connector: vulnerabilidades y CVE

SAP Cloud Connector tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses0
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-42955Baja (3.5)0.46%—12 ago 2025
Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful…
CVE-2024-25642Alta (7.4)0.54%—13 feb 2024
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the…
CVE-2023-49578Baja (3.5)0.27%—12 dic 2023
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no…
CVE-2021-33695Crítica (9.1)0.56%—15 sept 2021
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
CVE-2021-33694Media (4.8)0.46%—15 sept 2021
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed,…
CVE-2021-33693Media (6.8)0.54%—15 sept 2021
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.
CVE-2021-33692Alta (7.5)1.2%—15 sept 2021
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted…
CVE-2019-0247Crítica (9.8)1.3%—8 ene 2019
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVE-2019-0246Crítica (9.8)2.7%—8 ene 2019
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

Otros productos de SAP