← Back

Sap

sap

1,589 CVEs • 430 products

Products (430)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Approuter
approuter
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
2Abap Platform
Netweaver Application Server Abap
Jun 17, 2026
Aug 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection....Show more
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.Show less
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compr...Show more
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compromise of the installed Cockpit. This compromise could enable the attacker to view, modify and/or make unavailable any data associated with the Cockpit, leading to Information Disclosure.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Aug 12, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
1Sap
1Netweaver Knowledge Management
Jun 17, 2026
Aug 12, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limit...Show more
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.Show less
1Sap
1Netweaver Knowledge Management
Jun 17, 2026
Aug 12, 2020
N/A· v4
9.0 CRITICAL· v3
8.5 HIGH· v2
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessin...Show more
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.Show less
1Sap
1S/4 Hana Fiori Ui For General Ledger Accounting
Jun 17, 2026
Aug 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachm...Show more
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.Show less
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2020
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform...Show more
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method...Show more
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.Show less
1Sap
1Netweaver
Jun 17, 2026
Jul 14, 2020
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Inf...Show more
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an at...Show more
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Jul 14, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
1Sap
2Abap Platform
Netweaver Application Server Abap
Jun 17, 2026
Jul 14, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the vict...Show more
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site ScriptingShow less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Jul 14, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
1Sap
1Disclosure Management
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.
1Sap
1Solution Manager
Jun 17, 2026
Jul 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.