Sap Se Sap Hcm vulnerabilities
6 known vulnerabilities affecting sap_se/sap_hcm.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4LOW2
Vulnerabilities
Page 1 of 1
CVE-2025-42917P3MEDIUMCVSS 6.5vGBX01HR5 6052025-09-09
CVE-2025-42917 [MEDIUM] CWE-862 CVE-2025-42917: SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for
SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.
nvd
CVE-2025-42912P3MEDIUMCVSS 6.5vGBX01HR5 6052025-09-09
CVE-2025-42912 [MEDIUM] CWE-862 CVE-2025-42912: SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an au
SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.
nvd
CVE-2023-49577P4MEDIUMCVSS 6.1vS4HCMCIE 100vSAP_HRCIE 600+2 more2023-12-12
CVE-2023-49577 [MEDIUM] CWE-79 CVE-2023-49577: The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 6
The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
nvd
CVE-2024-47581P4MEDIUMCVSS 4.3vS4HCMGXX 1012024-12-10
CVE-2024-47581 [MEDIUM] CWE-862 CVE-2024-47581: SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.
nvd
CVE-2025-42913P4LOWCVSS 3.1vGBX01HR5 6052025-09-09
CVE-2025-42913 [LOW] CWE-862 CVE-2025-42913: Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authentica
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.
nvd
CVE-2025-42914P4LOWCVSS 3.1vGBX01HR5 6052025-09-09
CVE-2025-42914 [LOW] CWE-862 CVE-2025-42914: Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authentica
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.
nvd