Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Abap MEDIUM 6.5
CVE-2026-40135

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker…

Mitigation only
Fix from $1,600 2026-05-12
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-27682

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a…

Mitigation only
Fix from $1,600 2026-05-12
Human Capital Management MEDIUM 6.5
CVE-2026-34264

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-34257

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access…

Mitigation only
Fix from $1,600 2026-04-14
Manage Reference Structures MEDIUM 6.5
CVE-2026-27679

Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Java MEDIUM 6.1
CVE-2026-27674

Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Abap MEDIUM 5.0
CVE-2026-27688

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24316

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24309

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul…

Mitigation only
Fix from $1,600 2026-03-10
Business Server Pages MEDIUM 6.1
CVE-2026-24328

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th…

Mitigation only
Fix from $1,600 2026-02-10
Solution Tools Plug In HIGH 7.7
CVE-2026-24322

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow…

Mitigation only
Fix from $1,950 2026-02-10
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2026-24324

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in …

Mitigation only
Fix from $1,600 2026-02-10
Document Management System MEDIUM 6.1
CVE-2026-24323

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa…

Mitigation only
Fix from $1,600 2026-02-10
Commerce Cloud MEDIUM 5.3
CVE-2026-24321

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sens…

Mitigation only
Fix from $1,600 2026-02-10
Sap Basis HIGH 8.8
CVE-2026-23687

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …

Mitigation only
Fix from $1,950 2026-02-10
Advanced Planning And Optimization HIGH 7.7
CVE-2026-23689

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc…

Mitigation only
Fix from $1,950 2026-02-10
Business One MEDIUM 5.8
CVE-2026-24319

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information …

Mitigation only
Fix from $1,600 2026-02-10
Sap Basis MEDIUM 5.2
CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric…

Mitigation only
Fix from $1,600 2026-02-10
Netweaver As Abap Kernel CRITICAL 9.6
CVE-2026-0509

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…

Mitigation only
Fix from $2,300 2026-02-10
Businessobjects Business Intelligence Platform HIGH 8.1
CVE-2026-0508

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli…

Mitigation only
Fix from $1,950 2026-02-10
Document Management System MEDIUM 6.1
CVE-2026-0505

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could resul…

Mitigation only
Fix from $1,600 2026-02-10
Commerce Cloud MEDIUM 5.9
CVE-2026-23684

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart en…

Mitigation only
Fix from $1,600 2026-02-10
Netweaver Application Server Abap CRITICAL 9.9
CVE-2026-0488

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…

Mitigation only
Fix from $2,300 2026-02-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2026-0485

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server …

Mitigation only
Fix from $1,950 2026-02-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2026-0490

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen…

Mitigation only
Fix from $1,950 2026-02-10
Sap Basis MEDIUM 6.5
CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…

Mitigation only
Fix from $1,600 2026-02-10
Business Connector MEDIUM 6.1
CVE-2026-0514

Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsusp…

Mitigation only
Fix from $1,600 2026-01-13
Business Connector MEDIUM 6.8
CVE-2025-42894

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.1
CVE-2025-42893

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victi…

Mitigation only
Fix from $1,600 2025-11-11
Business Connector MEDIUM 6.8
CVE-2025-42892

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network acc…

Mitigation only
Fix from $1,600 2025-11-11