Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hana Database HIGH 8.8
CVE-2026-0492

SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially…

Patch available
Fix from $1,950 2026-01-13
Business Connector MEDIUM 6.8
CVE-2025-42894

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.1
CVE-2025-42893

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victi…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.8
CVE-2025-42892

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.1
CVE-2025-42886

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link an…

Mitigation only
Fix from $1,600 2025-11-11
Netweaver Application Server Java MEDIUM 5.3
CVE-2025-42926

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web appl…

Patch available
Fix from $1,600 2025-09-09
Supplier Relationship Management MEDIUM 6.1
CVE-2025-42920

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious…

Patch available
Fix from $1,600 2025-09-09
Sap Basis MEDIUM 5.4
CVE-2025-42936

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this …

Patch available
Fix from $1,600 2025-08-12
Sap Basis MEDIUM 6.1
CVE-2025-42956

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly av…

Patch available
Fix from $1,600 2025-07-08
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2025-42988

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the i…

Patch available
Fix from $1,600 2025-06-10
Businessobjects Business Intelligence HIGH 7.6
CVE-2025-23192

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. W…

Patch available
Fix from $1,950 2025-06-10
Netweaver CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…

Mitigation only
Fix from $2,300 2025-05-13
Supplier Relationship Management CRITICAL 9.8
CVE-2025-30012

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attac…

Mitigation only
Fix from $2,300 2025-05-13
Supplier Relationship Management HIGH 7.5
CVE-2025-30018

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi…

Mitigation only
Fix from $1,950 2025-05-13
Supplier Relationship Management MEDIUM 6.1
CVE-2025-30009

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which …

Mitigation only
Fix from $1,600 2025-05-13
Supplier Relationship Management MEDIUM 6.1
CVE-2025-30010

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…

Mitigation only
Fix from $1,600 2025-05-13
Supplier Relationship Management MEDIUM 5.3
CVE-2025-30011

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which…

Mitigation only
Fix from $1,600 2025-05-13
Netweaver CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…

Mitigation only
Fix from $2,300 2025-04-24
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2025-31332

Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify f…

Mitigation only
Fix from $1,950 2025-04-08
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2025-25245

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An…

Patch available
Fix from $1,600 2025-03-11
Sap Basis HIGH 7.5
CVE-2025-23193

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the ex…

Patch available
Fix from $1,950 2025-02-11
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2025-0064

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rig…

Patch available
Fix from $1,600 2025-02-11
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2025-0061

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user …

Patch available
Fix from $2,300 2025-01-14
Sap Basis HIGH 8.8
CVE-2025-0063

SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attack…

Patch available
Fix from $1,950 2025-01-14
Sap Basis HIGH 8.8
CVE-2025-0066

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor…

Patch available
Fix from $1,950 2025-01-14
Sap Basis MEDIUM 6.5
CVE-2025-0058

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request …

Patch available
Fix from $1,600 2025-01-14
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2025-0060

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sen…

Patch available
Fix from $1,600 2025-01-14
Sap Basis MEDIUM 5.3
CVE-2025-0053

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific…

Patch available
Fix from $1,600 2025-01-14
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2024-32732

Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restric…

Patch available
Fix from $1,600 2024-12-10
Host Agent HIGH 7.1
CVE-2024-47595

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t…

Mitigation only
Fix from $1,950 2024-11-12