← Back

Sap

sap

1,589 CVEs • 430 products

Products (430)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Approuter
approuter
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Upgrade Tools
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Oil Industry Solution Traders And Schedulers Workbench
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Brazil
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Project System
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Netweaver
May 6, 2026
Jun 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.
1Sap
1Netweaver
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
1Sap
1Businessobjects
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Sap
1Netweaver Java Application Server
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to SystemSelection.
1Sap
1Background Processing
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.
1Sap
1Profile Maintenance
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.
1Sap
1Netweaver Abap Application Server
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instruction...Show more
The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages.Show less
1Sap
1Netweaver Software Lifecycle Manager
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1.
1Sap
1Router
May 6, 2026
Apr 17, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which al...Show more
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain passwords via a brute-force attack that relies on timing differences in responses to incorrect password guesses, aka a timing side-channel attack.Show less
1Sap
1Business Object Processing Framework For Abap
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Print And Output Management
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Sap
1Hana
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
1Sap
1Enhancement Package
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from...Show more
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from third party information.Show less
1Sap
1Enterprise Portal
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via unspecified vectors.
1Sap
1Software Deployment Manager
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
1Sap
1Enterprise Portal
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.