Sap Se Sap Fiori vulnerabilities
3 known vulnerabilities affecting sap_se/sap_fiori.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2020-6283P4MEDIUMCVSS 6.1fixed in 750fixed in 752+3 more2020-09-09
CVE-2020-6283 [MEDIUM] CWE-79 CVE-2020-6283: SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the atta
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data rel
nvd
CVE-2026-24315P4MEDIUMCVSS 4.2vSAP_UI 754v755+4 more2026-06-09
CVE-2026-24315 [MEDIUM] CWE-35 CVE-2026-24315: SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls o
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Avail
nvd
CVE-2025-42941P4LOWCVSS 3.5vSAP_UI 7542025-08-12
CVE-2025-42941 [LOW] CWE-1022 CVE-2025-42941: SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external n
SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link () elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is necessary for certain configurations, the attacker does not n
nvd