← Back

Sap

sap

1,576 CVEs • 429 products

Products (429)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Business Object Processing Framework For Abap
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Print And Output Management
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Hana
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
1Sap
1Enhancement Package
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from...Show more
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from third party information.Show less
1Sap
1Enterprise Portal
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via unspecified vectors.
1Sap
1Software Deployment Manager
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
1Sap
1Enterprise Portal
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
1Sap
1Netweaver
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors.
1Sap
1Solution Manager
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via v...Show more
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol.Show less
1Sap
1Ccms Agent
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.
1Sap
2Cm Services
Cms Services
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors.
1Sap
1Adminadapter
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors.
1Sap
1Mobile Infrastructure
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in SAP Mobile Infrastructure allows remote attackers to obtain sensitive port information via unknown vectors, related to an "internal port scanning" issue.
1Sap
1Guided Procedures Archive Monitor
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other identity information via unknown vectors.
1Sap
1J2ee Engine
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vectors.
1Sap
1Ccms / Database Monitor
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors.
1Sap
1Bi Universal Data Integration
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to the J2EE schema.
1Sap
1Netweaver
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote a...Show more
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP.Show less
1Sap
2Netweaver
Netweaver Exchange Infrastructure (bc Xi)
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors rela...Show more
Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to the ESR application and a DIR error.Show less
1Sap
1Netweaver
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.