Application Interface Framework SAP Application Interface Framework

Do you want an email whenever new security vulnerabilities are reported in SAP Application Interface Framework?

By the Year

In 2024 there have been 1 vulnerability in SAP Application Interface Framework with an average score of 9.1 out of ten. Last year Application Interface Framework had 3 security vulnerabilities published. At the current rates, it appears that the number of vulnerabilities last year and this year may equal out. However, the average CVE base score of the vulnerabilities in 2024 is greater by 4.33.

Year Vulnerabilities Average Score
2024 1 9.10
2023 3 4.77
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Application Interface Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent SAP Application Interface Framework Security Vulnerabilities

In SAP Application Interface Framework File Adapter - version 702, a high privilege user

CVE-2024-21737 9.1 - Critical - January 09, 2024

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.

Code Injection

The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required

CVE-2023-29111 4.3 - Medium - April 11, 2023

The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application

CVE-2023-29110 5.4 - Medium - April 11, 2023

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

XSS

The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application

CVE-2023-29109 4.6 - Medium - April 11, 2023

The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.

CSV Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for SAP Application Interface Framework or by SAP? Click the Watch button to subscribe.

SAP
Vendor

subscribe