SAP records
1,605 published records for vendor sap.
Researcher profile
- Entered KEV
- 14 · 0.9%
- Weaponized
- 29 · 1.8%
- Pre-auth RCE
- 101
- With a fix record
- 0.9%
- Median publish → KEV
- 1575 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')264
- CWE-862 Missing Authorization123
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer95
- CWE-20 Improper Input Validation85
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor68
- CWE-94 Improper Control of Generation of Code ('Code Injection')45
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,605 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2025-31324Weaponized | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Critical9.8 | KEV | 99.5% | Apr 24, 2025 |
99Now | CVE-2022-22536Weaponized | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher sap · content server · CWE-444 | Critical10.0 | KEV | 97.9% | Feb 9, 2022 |
98Now | CVE-2020-6207Weaponized | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication forsap · solution manager · CWE-306 | Critical9.8 | KEV | 98.1% | Mar 10, 2020 |
98Now | CVE-2020-6287Weaponized | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows ansap · netweaver application server java · CWE-306 | Critical10.0 | KEV | 94.7% | Jul 14, 2020 |
90Now | CVE-2016-2386Weaponized | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands vsap · netweaver application server java · CWE-89 | Critical9.8 | KEV | 71.5% | Feb 16, 2016 |
89Now | CVE-2017-12637Weaponized | Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allowssap · netweaver application server java · CWE-22 | High7.5 | KEV | 95.1% | Aug 7, 2017 |
76This week | CVE-2021-38163Weaponized | SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrasap · netweaver · CWE-22 | High8.8 | KEV | 36.0% | Sep 14, 2021 |
75This week | CVE-2010-5326Weaponized | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows rsap · netweaver application server java · CWE-306 | Critical10.0 | KEV | 17.8% | May 13, 2016 |
74This week | CVE-2016-3976Weaponized | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dosap · netweaver application server java · CWE-22 | High7.5 | KEV | 47.3% | Apr 7, 2016 |
71This week | CVE-2019-0344Weaponized | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possisap · commerce cloud · CWE-502 | Critical9.8 | KEV | 7.1% | Aug 14, 2019 |
70This week | CVE-2025-42999Weaponized | Insecure Deserialization in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-502 | Critical9.1 | KEV | 13.9% | May 12, 2025 |
67This week | CVE-2010-0219Weaponized | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default passapache · axis2 · CWE-255 | Critical10.0 | — | 90.9% | Oct 18, 2010 |
67This week | CVE-2016-2388Weaponized | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a craftedsap · netweaver application server java · CWE-200 | Medium5.3 | KEV | 52.2% | Feb 16, 2016 |
65This week | CVE-2018-2380Weaponized | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thusap · customer relationship management · CWE-22 | Medium6.6 | KEV | 28.9% | Mar 1, 2018 |
64This week | CVE-2008-0244Weaponized | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in execsap · maxdb · CWE-20 | Critical10.0 | — | 80.3% | Jan 11, 2008 |
63This week | CVE-2016-9563Weaponized | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tsap · netweaver application server java · CWE-611 | Medium6.5 | KEV | 24.2% | Nov 22, 2016 |
62This week | CVE-2024-41730No exploit | Missing Authentication check in SAP BusinessObjects Business Intelligence Platformsap · business objects business intelligence platform · CWE-862 | Critical9.8 | — | 75.9% | Aug 13, 2024 |
60This week | CVE-2021-33690Proof of concept | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service vsap · netweaver development infrastructure · CWE-918 | Critical9.9 | — | 69.1% | Sep 15, 2021 |
60This week | CVE-2009-4988Weaponized | Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbsap · business one 2005-a · CWE-119 | Critical10.0 | — | 65.5% | Aug 25, 2010 |
52Plan | CVE-2008-0621Weaponized | Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary csap · sapgui · CWE-119 | High7.5 | — | 73.4% | Feb 6, 2008 |
51Plan | CVE-2007-3614Weaponized | Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers sap · sap db | High7.5 | — | 70.0% | Jul 6, 2007 |
51Plan | CVE-2007-3605Weaponized | Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remotsap · enjoysap | High7.6 | — | 69.9% | Jul 6, 2007 |
51Plan | CVE-2021-21480No exploit | SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).sap · manufacturing integration and intelligence · CWE-94 | High8.8 | — | 52.1% | Mar 9, 2021 |
51Plan | CVE-2010-2590Weaponized | Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reporsap · crystal reports · CWE-119 | Critical9.3 | — | 46.8% | Dec 21, 2010 |
51Plan | CVE-2007-3624Proof of concept | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long strsap · sap message server | Critical10.0 | — | 36.8% | Jul 9, 2007 |
- CVE-2025-3132499Now
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sap · netweaverApr 24, 2025
- CVE-2022-2253699Now
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher
CriticalCVSS 10.0KEVWeaponizedEPSS 98%sap · content serverFeb 9, 2022
- CVE-2020-620798Now
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for
CriticalCVSS 9.8KEVWeaponizedEPSS 98%sap · solution managerMar 10, 2020
- CVE-2020-628798Now
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an
CriticalCVSS 10.0KEVWeaponizedEPSS 95%sap · netweaver application server javaJul 14, 2020
- CVE-2016-238690Now
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v
CriticalCVSS 9.8KEVWeaponizedEPSS 72%sap · netweaver application server javaFeb 16, 2016
- CVE-2017-1263789Now
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows
HighCVSS 7.5KEVWeaponizedEPSS 95%sap · netweaver application server javaAug 7, 2017
- CVE-2021-3816376This week
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administra
HighCVSS 8.8KEVWeaponizedEPSS 36%sap · netweaverSep 14, 2021
- CVE-2010-532675This week
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows r
CriticalCVSS 10.0KEVWeaponizedEPSS 18%sap · netweaver application server javaMay 13, 2016
- CVE-2016-397674This week
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot do
HighCVSS 7.5KEVWeaponizedEPSS 47%sap · netweaver application server javaApr 7, 2016
- CVE-2019-034471This week
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possi
CriticalCVSS 9.8KEVWeaponizedEPSS 7%sap · commerce cloudAug 14, 2019
- CVE-2025-4299970This week
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
CriticalCVSS 9.1KEVWeaponizedEPSS 14%sap · netweaverMay 12, 2025
- CVE-2010-021967This week
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default pass
CriticalCVSS 10.0WeaponizedEPSS 91%apache · axis2Oct 18, 2010
- CVE-2016-238867This week
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted
MediumCVSS 5.3KEVWeaponizedEPSS 52%sap · netweaver application server javaFeb 16, 2016
- CVE-2018-238065This week
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thu
MediumCVSS 6.6KEVWeaponizedEPSS 29%sap · customer relationship managementMar 1, 2018
- CVE-2008-024464This week
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec
CriticalCVSS 10.0WeaponizedEPSS 80%sap · maxdbJan 11, 2008
- CVE-2016-956363This week
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t
MediumCVSS 6.5KEVWeaponizedEPSS 24%sap · netweaver application server javaNov 22, 2016
- CVE-2024-4173062This week
Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
CriticalCVSS 9.8No exploitEPSS 76%sap · business objects business intelligence platformAug 13, 2024
- CVE-2021-3369060This week
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service v
CriticalCVSS 9.9Proof of conceptEPSS 69%sap · netweaver development infrastructureSep 15, 2021
- CVE-2009-498860This week
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arb
CriticalCVSS 10.0WeaponizedEPSS 66%sap · business one 2005-aAug 25, 2010
- CVE-2008-062152Plan
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary c
HighCVSS 7.5WeaponizedEPSS 73%sap · sapguiFeb 6, 2008
- CVE-2007-361451Plan
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers
HighCVSS 7.5WeaponizedEPSS 70%sap · sap dbJul 6, 2007
- CVE-2007-360551Plan
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remot
HighCVSS 7.6WeaponizedEPSS 70%sap · enjoysapJul 6, 2007
- CVE-2021-2148051Plan
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).
HighCVSS 8.8No exploitEPSS 52%sap · manufacturing integration and intelligenceMar 9, 2021
- CVE-2010-259051Plan
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Repor
CriticalCVSS 9.3WeaponizedEPSS 47%sap · crystal reportsDec 21, 2010
- CVE-2007-362451Plan
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long str
CriticalCVSS 10.0Proof of conceptEPSS 37%sap · sap message serverJul 9, 2007