← Back

Sap

sap

1,589 CVEs • 430 products

Products (430)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Approuter
approuter
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Netweaver
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors.
1Sap
1Solution Manager
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via v...Show more
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol.Show less
1Sap
1Ccms Agent
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.
1Sap
2Cm Services
Cms Services
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors.
1Sap
1Adminadapter
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors.
1Sap
1Mobile Infrastructure
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in SAP Mobile Infrastructure allows remote attackers to obtain sensitive port information via unknown vectors, related to an "internal port scanning" issue.
1Sap
1Guided Procedures Archive Monitor
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other identity information via unknown vectors.
1Sap
1J2ee Engine
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vectors.
1Sap
1Ccms / Database Monitor
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors.
1Sap
1Bi Universal Data Integration
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to the J2EE schema.
1Sap
1Netweaver
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote a...Show more
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP.Show less
1Sap
2Netweaver
Netweaver Exchange Infrastructure (bc Xi)
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors rela...Show more
Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to the ESR application and a DIR error.Show less
1Sap
1Netweaver
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.
1Sap
1Customer Relationship Management
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
1Sap
1Netweaver
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.
1Sap
2Netweaver
Netweaver Solution Manager
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Sap
1Emr Unwired
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Sap
1Customer Relationship Management
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
1Sap
1Netweaver
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Sap
1Network Interface Router
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.