Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Business Connector MEDIUM 6.1
CVE-2025-42886

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link an…

Mitigation only
Fix from $1,600 2025-11-11
Netweaver CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…

Mitigation only
Fix from $2,300 2025-05-13
Supplier Relationship Management CRITICAL 9.8
CVE-2025-30012

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac…

Mitigation only
Fix from $2,300 2025-05-13
Supplier Relationship Management HIGH 7.5
CVE-2025-30018

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi…

Mitigation only
Fix from $1,950 2025-05-13
Supplier Relationship Management MEDIUM 6.1
CVE-2025-30009

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which …

Mitigation only
Fix from $1,600 2025-05-13
Supplier Relationship Management MEDIUM 6.1
CVE-2025-30010

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…

Mitigation only
Fix from $1,600 2025-05-13
Supplier Relationship Management MEDIUM 5.3
CVE-2025-30011

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…

Mitigation only
Fix from $1,600 2025-05-13
Netweaver CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…

Mitigation only
Fix from $2,300 2025-04-24
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2025-31332

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify f…

Mitigation only
Fix from $1,950 2025-04-08
Host Agent HIGH 7.1
CVE-2024-47595

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t…

Mitigation only
Fix from $1,950 2024-11-12
Netweaver Enterprise Portal MEDIUM 5.4
CVE-2024-47594

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC ser…

Mitigation only
Fix from $1,600 2024-10-08
Commerce Backoffice MEDIUM 5.4
CVE-2024-45278

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful …

Mitigation only
Fix from $1,600 2024-10-08
S\/4 Hana MEDIUM 5.3
CVE-2024-45282

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property …

Mitigation only
Fix from $1,600 2024-10-08
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2024-37179

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting…

Mitigation only
Fix from $1,600 2024-10-08
Student Life Cycle Management MEDIUM 5.4
CVE-2024-42373

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of…

Mitigation only
Fix from $1,600 2024-08-13
Document Builder MEDIUM 5.3
CVE-2024-39591

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing lo…

Mitigation only
Fix from $1,600 2024-08-13
Bex Web Java Runtime Export Web Service HIGH 8.2
CVE-2024-42374

BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve in…

Mitigation only
Fix from $1,950 2024-08-13
Shared Service Framework MEDIUM 6.5
CVE-2024-42376

SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On succ…

Mitigation only
Fix from $1,600 2024-08-13
Crm Abap Insights Management MEDIUM 5.0
CVE-2024-41737

SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP re…

Mitigation only
Fix from $1,600 2024-08-13
Commerce Backoffice MEDIUM 5.4
CVE-2024-41735

SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact…

Mitigation only
Fix from $1,600 2024-08-13
Business Objects Business Intelligence Platform CRITICAL 9.8
CVE-2024-41730EPSS 76%

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo…

Mitigation only
Fix from $2,300 2024-08-13
Netweaver Application Server Abap MEDIUM 5.4
CVE-2024-41732

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on t…

Mitigation only
Fix from $1,600 2024-08-13
Commerce MEDIUM 5.3
CVE-2024-41733

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to lear…

Mitigation only
Fix from $1,600 2024-08-13
Commerce Cloud CRITICAL 9.1
CVE-2024-33003

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile number…

Mitigation only
Fix from $2,300 2024-08-13
Netweaver Abap MEDIUM 6.3
CVE-2024-33005

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java)…

Mitigation only
Fix from $1,600 2024-08-13
Customer Relationship Management S4fnd MEDIUM 6.5
CVE-2024-37175

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow a…

Mitigation only
Fix from $1,600 2024-07-09
S4core MEDIUM 5.4
CVE-2024-37172

SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation o…

Mitigation only
Fix from $1,600 2024-07-09
Saptmui MEDIUM 5.0
CVE-2024-37171

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerabl…

Mitigation only
Fix from $1,600 2024-07-09
Business Workflow MEDIUM 5.0
CVE-2024-34689

WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by speciall…

Mitigation only
Fix from $1,600 2024-07-09
Customer Relationship Management S4fnd HIGH 7.7
CVE-2024-39598

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially craftin…

Mitigation only
Fix from $1,950 2024-07-09