← Back

Sap

sap

1,589 CVEs • 430 products

Products (430)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Approuter
approuter
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Mobile Platform
Nov 21, 2024
Aug 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.
1Sap
1Businessobjects Edge
Nov 21, 2024
Aug 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.
1Sap
1Businessobjects Edge
Nov 21, 2024
Aug 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682.
1Sap
1Businessobjects Edge
Nov 21, 2024
Aug 9, 2021
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrit...Show more
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS...Show more
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.Show less
1Sap
2Netweaver Abap
Netweaver Application Server Abap
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT...Show more
SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.77, 7.81, 7.84, allows an attacker to send overlong content in the RFC request type thereby crashing the corresponding work process because of memory corruption vulnerability. The work process will attempt to restart itself after the crash and hence the impact on the availability is low.Show less
1Sap
2Internet Communication Manager
Web Dispatcher
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT,...Show more
SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73, WEBDISP 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, KERNEL 7.21, 7.22, 7.49, 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, process invalid HTTP header. The incorrect handling of the invalid Transfer-Encoding header in a particular manner leads to a possibility of HTTP Request Smuggling attack. An attacker could exploit this vulnerability to bypass web application firewall protection, divert sensitive data such as customer requests, session credentials, etc.Show less
1Sap
1Lumira Server
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious scri...Show more
SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious script on SAP Lumira Server. The execution of the script content, by a victim registered on SAP Lumira Server, could compromise the confidentiality and integrity of SAP Lumira content.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unava...Show more
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the application.Show less
1Sap
13d Visual Enterprise Viewer
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailab...Show more
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailable until the user restarts the application.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code...Show more
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.Show less
1Sap
2Netweaver Abap
Netweaver Application Server Abap
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure.
1Sap
1Customer Relationship Management
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
1Sap
1Netweaver Guided Procedures
Jun 17, 2026
Jul 14, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. T...Show more
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. The impact of missing authorization could result to abuse of functionality restricted to a particular user group, and could allow unauthorized users to read, modify or delete restricted data.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter a...Show more
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.Show less
1Sap
1Businessobjects Web Intelligence
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend...Show more
Under certain conditions, SAP Business Objects Web Intelligence (BI Launchpad) versions - 420, 430, allows an attacker to access jsp source code, through SDK calls, of Analytical Reporting bundle, a part of the frontend application, which would otherwise be restricted.Show less
1Sap
2Netweaver Abap
Netweaver Application Server Abap
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format,...Show more
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.Show less
1Sap
1Mobile Sdk Certificate Provider
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is requir...Show more
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality integrity and availability.Show less
1Sap
1Commerce Cloud
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.