Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Abap MEDIUM 6.5
CVE-2026-40135

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker…

Mitigation only
Fix from $1,600 2026-05-12
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-27682

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), a…

Mitigation only
Fix from $1,600 2026-05-12
Human Capital Management MEDIUM 6.5
CVE-2026-34264

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Abap MEDIUM 6.1
CVE-2026-34257

Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if access…

Mitigation only
Fix from $1,600 2026-04-14
Manage Reference Structures MEDIUM 6.5
CVE-2026-27679

Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete chil…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Java MEDIUM 6.1
CVE-2026-27674

Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in…

Mitigation only
Fix from $1,600 2026-04-14
Netweaver Application Server Abap MEDIUM 5.0
CVE-2026-27688

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24316

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or e…

Mitigation only
Fix from $1,600 2026-03-10
Netweaver Application Server Abap MEDIUM 6.4
CVE-2026-24309

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function modul…

Mitigation only
Fix from $1,600 2026-03-10
Business Server Pages MEDIUM 6.1
CVE-2026-24328

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect th…

Mitigation only
Fix from $1,600 2026-02-10
Solution Tools Plug In HIGH 7.7
CVE-2026-24322

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allow…

Mitigation only
Fix from $1,950 2026-02-10
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2026-24324

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in …

Mitigation only
Fix from $1,600 2026-02-10
Document Management System MEDIUM 6.1
CVE-2026-24323

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sa…

Mitigation only
Fix from $1,600 2026-02-10
Commerce Cloud MEDIUM 5.3
CVE-2026-24321

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sens…

Mitigation only
Fix from $1,600 2026-02-10
Sap Basis HIGH 8.8
CVE-2026-23687

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …

Mitigation only
Fix from $1,950 2026-02-10
Advanced Planning And Optimization HIGH 7.7
CVE-2026-23689

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc…

Mitigation only
Fix from $1,950 2026-02-10
Business One MEDIUM 5.8
CVE-2026-24319

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information …

Mitigation only
Fix from $1,600 2026-02-10
Sap Basis MEDIUM 5.2
CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restric…

Mitigation only
Fix from $1,600 2026-02-10
Netweaver As Abap Kernel CRITICAL 9.6
CVE-2026-0509

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…

Mitigation only
Fix from $2,300 2026-02-10
Businessobjects Business Intelligence Platform HIGH 8.1
CVE-2026-0508

The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the appli…

Mitigation only
Fix from $1,950 2026-02-10
Document Management System MEDIUM 6.1
CVE-2026-0505

The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could resul…

Mitigation only
Fix from $1,600 2026-02-10
Commerce Cloud MEDIUM 5.9
CVE-2026-23684

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart en…

Mitigation only
Fix from $1,600 2026-02-10
Netweaver Application Server Abap CRITICAL 9.9
CVE-2026-0488

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…

Mitigation only
Fix from $2,300 2026-02-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2026-0485

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server …

Mitigation only
Fix from $1,950 2026-02-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2026-0490

SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted endpoint that breaks the authen…

Mitigation only
Fix from $1,950 2026-02-10
Sap Basis MEDIUM 6.5
CVE-2026-0484

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…

Mitigation only
Fix from $1,600 2026-02-10
Business Connector MEDIUM 6.1
CVE-2026-0514

Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsusp…

Mitigation only
Fix from $1,600 2026-01-13
Netweaver Application Server Abap HIGH 8.1
CVE-2026-0506

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC functi…

Patch available
Fix from $1,950 2026-01-13
Introscope Enterprise Manager HIGH 8.8
CVE-2026-0500

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat…

Patch available
Fix from $1,950 2026-01-13
S\/4 Hana HIGH 7.2
CVE-2026-0498

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC…

Patch available
Fix from $1,950 2026-01-13