cbcvebase.

Sap Se Sap Fiori App vulnerabilities

9 known vulnerabilities affecting sap_se/sap_fiori_app.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM8

Vulnerabilities

Page 1 of 1
CVE-2026-0511P3HIGHCVSS 8.1vUIAPFI70 500v600+12 more2026-01-13
CVE-2026-0511 [HIGH] CWE-862 CVE-2026-0511: SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks fo SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
nvd
CVE-2026-0496P3MEDIUMCVSS 6.6vUIAPFI70 500v600+12 more2026-01-13
CVE-2026-0496 [MEDIUM] CWE-434 CVE-2026-0496: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
nvd
CVE-2026-0495P4MEDIUMCVSS 5.1vUIAPFI70 500v600+12 more2026-01-13
CVE-2026-0495 [MEDIUM] CWE-15 CVE-2026-0495: SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send u SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
nvd
CVE-2024-25643P4MEDIUMCVSS 4.3v6052024-02-13
CVE-2024-25643 [MEDIUM] CWE-862 CVE-2024-25643: The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access information that the user should not have access to. There is no impact on integrity and availability.
nvd
CVE-2026-23683P4MEDIUMCVSS 4.3vS4CORE 102v103+3 more2026-01-27
CVE-2026-23683 [MEDIUM] CWE-862 CVE-2026-23683: SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks fo SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.
nvd
CVE-2026-23688P4MEDIUMCVSS 4.3vS4CORE 102v103+4 more2026-02-10
CVE-2026-23688 [MEDIUM] CWE-862 CVE-2026-23688: SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an aut SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.
nvd
CVE-2025-42923P4MEDIUMCVSS 4.3vUIS4HOP1 600v700+2 more2025-09-09
CVE-2025-42923 [MEDIUM] CWE-352 CVE-2025-42923: Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated use Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and availability of the application.
nvd
CVE-2026-0493P4MEDIUMCVSS 4.3vUIAPFI70 500v600+14 more2026-01-13
CVE-2026-0493 [MEDIUM] CWE-352 CVE-2026-0493: Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Recon Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an authenticated user causing low impact on i
nvd
CVE-2026-0494P4MEDIUMCVSS 4.3vUIAPFI70 500v600+6 more2026-01-13
CVE-2026-0494 [MEDIUM] CWE-497 CVE-2026-0494: Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an att Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.
nvd
Sap Se Sap Fiori App vulnerabilities | cvebase