Записи SAP
1 605 опубликованных записей вендора sap.
Профиль для исследователя
- Попали в KEV
- 14 · 0,9 %
- С эксплойтом
- 29 · 1,8 %
- Pre-auth RCE
- 101
- С записью об исправлении
- 0,9 %
- Медиана: публикация → KEV
- 1575 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')264
- CWE-862 Missing Authorization123
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer95
- CWE-20 Improper Input Validation85
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor68
- CWE-94 Improper Control of Generation of Code ('Code Injection')45
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 605 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2025-31324Готовый эксплойт | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Критическая9,8 | KEV | 99,5 % | 24 апр. 2025 г. |
99Срочно | CVE-2022-22536Готовый эксплойт | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher sap · content server · CWE-444 | Критическая10,0 | KEV | 97,9 % | 9 февр. 2022 г. |
98Срочно | CVE-2020-6207Готовый эксплойт | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication forsap · solution manager · CWE-306 | Критическая9,8 | KEV | 98,1 % | 10 мар. 2020 г. |
98Срочно | CVE-2020-6287Готовый эксплойт | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows ansap · netweaver application server java · CWE-306 | Критическая10,0 | KEV | 94,7 % | 14 июл. 2020 г. |
90Срочно | CVE-2016-2386Готовый эксплойт | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands vsap · netweaver application server java · CWE-89 | Критическая9,8 | KEV | 71,5 % | 16 февр. 2016 г. |
89Срочно | CVE-2017-12637Готовый эксплойт | Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allowssap · netweaver application server java · CWE-22 | Высокая7,5 | KEV | 95,1 % | 7 авг. 2017 г. |
76На этой неделе | CVE-2021-38163Готовый эксплойт | SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrasap · netweaver · CWE-22 | Высокая8,8 | KEV | 36,0 % | 14 сент. 2021 г. |
75На этой неделе | CVE-2010-5326Готовый эксплойт | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows rsap · netweaver application server java · CWE-306 | Критическая10,0 | KEV | 17,8 % | 13 мая 2016 г. |
74На этой неделе | CVE-2016-3976Готовый эксплойт | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dosap · netweaver application server java · CWE-22 | Высокая7,5 | KEV | 47,3 % | 7 апр. 2016 г. |
71На этой неделе | CVE-2019-0344Готовый эксплойт | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possisap · commerce cloud · CWE-502 | Критическая9,8 | KEV | 7,1 % | 14 авг. 2019 г. |
70На этой неделе | CVE-2025-42999Готовый эксплойт | Insecure Deserialization in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-502 | Критическая9,1 | KEV | 13,9 % | 12 мая 2025 г. |
67На этой неделе | CVE-2010-0219Готовый эксплойт | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default passapache · axis2 · CWE-255 | Критическая10,0 | — | 90,9 % | 18 окт. 2010 г. |
67На этой неделе | CVE-2016-2388Готовый эксплойт | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a craftedsap · netweaver application server java · CWE-200 | Средняя5,3 | KEV | 52,2 % | 16 февр. 2016 г. |
65На этой неделе | CVE-2018-2380Готовый эксплойт | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thusap · customer relationship management · CWE-22 | Средняя6,6 | KEV | 28,9 % | 1 мар. 2018 г. |
64На этой неделе | CVE-2008-0244Готовый эксплойт | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in execsap · maxdb · CWE-20 | Критическая10,0 | — | 80,3 % | 11 янв. 2008 г. |
63На этой неделе | CVE-2016-9563Готовый эксплойт | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tsap · netweaver application server java · CWE-611 | Средняя6,5 | KEV | 24,2 % | 22 нояб. 2016 г. |
62На этой неделе | CVE-2024-41730Эксплойта нет | Missing Authentication check in SAP BusinessObjects Business Intelligence Platformsap · business objects business intelligence platform · CWE-862 | Критическая9,8 | — | 75,9 % | 13 авг. 2024 г. |
60На этой неделе | CVE-2021-33690Proof of concept | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service vsap · netweaver development infrastructure · CWE-918 | Критическая9,9 | — | 69,1 % | 15 сент. 2021 г. |
60На этой неделе | CVE-2009-4988Готовый эксплойт | Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbsap · business one 2005-a · CWE-119 | Критическая10,0 | — | 65,5 % | 25 авг. 2010 г. |
52В плане | CVE-2008-0621Готовый эксплойт | Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary csap · sapgui · CWE-119 | Высокая7,5 | — | 73,4 % | 6 февр. 2008 г. |
51В плане | CVE-2007-3614Готовый эксплойт | Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers sap · sap db | Высокая7,5 | — | 70,0 % | 6 июл. 2007 г. |
51В плане | CVE-2007-3605Готовый эксплойт | Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remotsap · enjoysap | Высокая7,6 | — | 69,9 % | 6 июл. 2007 г. |
51В плане | CVE-2021-21480Эксплойта нет | SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).sap · manufacturing integration and intelligence · CWE-94 | Высокая8,8 | — | 52,1 % | 9 мар. 2021 г. |
51В плане | CVE-2010-2590Готовый эксплойт | Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reporsap · crystal reports · CWE-119 | Критическая9,3 | — | 46,8 % | 21 дек. 2010 г. |
51В плане | CVE-2007-3624Proof of concept | Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long strsap · sap message server | Критическая10,0 | — | 36,8 % | 9 июл. 2007 г. |
- CVE-2025-3132499Срочно
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sap · netweaver24 апр. 2025 г.
- CVE-2022-2253699Срочно
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %sap · content server9 февр. 2022 г.
- CVE-2020-620798Срочно
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %sap · solution manager10 мар. 2020 г.
- CVE-2020-628798Срочно
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %sap · netweaver application server java14 июл. 2020 г.
- CVE-2016-238690Срочно
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %sap · netweaver application server java16 февр. 2016 г.
- CVE-2017-1263789Срочно
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 95 %sap · netweaver application server java7 авг. 2017 г.
- CVE-2021-3816376На этой неделе
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administra
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 36 %sap · netweaver14 сент. 2021 г.
- CVE-2010-532675На этой неделе
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows r
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 18 %sap · netweaver application server java13 мая 2016 г.
- CVE-2016-397674На этой неделе
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot do
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 47 %sap · netweaver application server java7 апр. 2016 г.
- CVE-2019-034471На этой неделе
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 7 %sap · commerce cloud14 авг. 2019 г.
- CVE-2025-4299970На этой неделе
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 14 %sap · netweaver12 мая 2025 г.
- CVE-2010-021967На этой неделе
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default pass
КритическаяCVSS 10,0Готовый эксплойтEPSS 91 %apache · axis218 окт. 2010 г.
- CVE-2016-238867На этой неделе
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 52 %sap · netweaver application server java16 февр. 2016 г.
- CVE-2018-238065На этой неделе
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thu
СредняяCVSS 6,6KEVГотовый эксплойтEPSS 29 %sap · customer relationship management1 мар. 2018 г.
- CVE-2008-024464На этой неделе
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec
КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %sap · maxdb11 янв. 2008 г.
- CVE-2016-956363На этой неделе
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 24 %sap · netweaver application server java22 нояб. 2016 г.
- CVE-2024-4173062На этой неделе
Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
КритическаяCVSS 9,8Эксплойта нетEPSS 76 %sap · business objects business intelligence platform13 авг. 2024 г.
- CVE-2021-3369060На этой неделе
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service v
КритическаяCVSS 9,9Proof of conceptEPSS 69 %sap · netweaver development infrastructure15 сент. 2021 г.
- CVE-2009-498860На этой неделе
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arb
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sap · business one 2005-a25 авг. 2010 г.
- CVE-2008-062152В плане
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary c
ВысокаяCVSS 7,5Готовый эксплойтEPSS 73 %sap · sapgui6 февр. 2008 г.
- CVE-2007-361451В плане
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers
ВысокаяCVSS 7,5Готовый эксплойтEPSS 70 %sap · sap db6 июл. 2007 г.
- CVE-2007-360551В плане
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remot
ВысокаяCVSS 7,6Готовый эксплойтEPSS 70 %sap · enjoysap6 июл. 2007 г.
- CVE-2021-2148051В плане
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment).
ВысокаяCVSS 8,8Эксплойта нетEPSS 52 %sap · manufacturing integration and intelligence9 мар. 2021 г.
- CVE-2010-259051В плане
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Repor
КритическаяCVSS 9,3Готовый эксплойтEPSS 47 %sap · crystal reports21 дек. 2010 г.
- CVE-2007-362451В плане
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long str
КритическаяCVSS 10,0Proof of conceptEPSS 37 %sap · sap message server9 июл. 2007 г.