Skip to content
Noroxi

SAP records

1,605 published records for vendor sap.

All records

1,605 records
  • Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sap · netweaverApr 24, 2025

  • SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher

    CriticalCVSS 10.0KEVWeaponizedEPSS 98%

    sap · content serverFeb 9, 2022

  • SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    sap · solution managerMar 10, 2020

  • SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an

    CriticalCVSS 10.0KEVWeaponizedEPSS 95%

    sap · netweaver application server javaJul 14, 2020

  • SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v

    CriticalCVSS 9.8KEVWeaponizedEPSS 72%

    sap · netweaver application server javaFeb 16, 2016

  • Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows

    HighCVSS 7.5KEVWeaponizedEPSS 95%

    sap · netweaver application server javaAug 7, 2017

  • CVE-2021-38163
    76This week

    SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administra

    HighCVSS 8.8KEVWeaponizedEPSS 36%

    sap · netweaverSep 14, 2021

  • CVE-2010-5326
    75This week

    The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows r

    CriticalCVSS 10.0KEVWeaponizedEPSS 18%

    sap · netweaver application server javaMay 13, 2016

  • CVE-2016-3976
    74This week

    Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot do

    HighCVSS 7.5KEVWeaponizedEPSS 47%

    sap · netweaver application server javaApr 7, 2016

  • CVE-2019-0344
    71This week

    Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possi

    CriticalCVSS 9.8KEVWeaponizedEPSS 7%

    sap · commerce cloudAug 14, 2019

  • CVE-2025-42999
    70This week

    Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

    CriticalCVSS 9.1KEVWeaponizedEPSS 14%

    sap · netweaverMay 12, 2025

  • CVE-2010-0219
    67This week

    Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default pass

    CriticalCVSS 10.0WeaponizedEPSS 91%

    apache · axis2Oct 18, 2010

  • CVE-2016-2388
    67This week

    The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted

    MediumCVSS 5.3KEVWeaponizedEPSS 52%

    sap · netweaver application server javaFeb 16, 2016

  • CVE-2018-2380
    65This week

    SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thu

    MediumCVSS 6.6KEVWeaponizedEPSS 29%

    sap · customer relationship managementMar 1, 2018

  • CVE-2008-0244
    64This week

    SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec

    CriticalCVSS 10.0WeaponizedEPSS 80%

    sap · maxdbJan 11, 2008

  • CVE-2016-9563
    63This week

    BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t

    MediumCVSS 6.5KEVWeaponizedEPSS 24%

    sap · netweaver application server javaNov 22, 2016

  • CVE-2024-41730
    62This week

    Missing Authentication check in SAP BusinessObjects Business Intelligence Platform

    CriticalCVSS 9.8No exploitEPSS 76%

    sap · business objects business intelligence platformAug 13, 2024

  • CVE-2021-33690
    60This week

    Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service v

    CriticalCVSS 9.9Proof of conceptEPSS 69%

    sap · netweaver development infrastructureSep 15, 2021

  • CVE-2009-4988
    60This week

    Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arb

    CriticalCVSS 10.0WeaponizedEPSS 66%

    sap · business one 2005-aAug 25, 2010

  • Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary c

    HighCVSS 7.5WeaponizedEPSS 73%

    sap · sapguiFeb 6, 2008

  • Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers

    HighCVSS 7.5WeaponizedEPSS 70%

    sap · sap dbJul 6, 2007

  • Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remot

    HighCVSS 7.6WeaponizedEPSS 70%

    sap · enjoysapJul 6, 2007

  • SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).

    HighCVSS 8.8No exploitEPSS 52%

    sap · manufacturing integration and intelligenceMar 9, 2021

  • Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Repor

    CriticalCVSS 9.3WeaponizedEPSS 47%

    sap · crystal reportsDec 21, 2010

  • Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long str

    CriticalCVSS 10.0Proof of conceptEPSS 37%

    sap · sap message serverJul 9, 2007