Skip to main content

Daily materialized evidence profile

Vendor sap

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,580
CVEs with mentions
447
Total mentions
794
CVEs with KEV
14
CVEs with PoC
1

Attack vector counts

Network
1,368
Adjacent network
22
Local
185
Physical
5

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2025-31324

Published Apr 24, 2025

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries th…

CVSS 10.0 · Critical
evidence mentions
39
Buzz score
75.0
KEV listed

CVE-2025-42999

Published May 13, 2025

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to…

CVSS 9.1 · Critical
evidence mentions
15
Buzz score
72.7
KEV listed

CVE-2020-6287

Published Jul 14, 2020

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication…

CVSS 10.0 · Critical
evidence mentions
19
Buzz score
69.5
KEV listed

CVE-2020-6207

Published Mar 10, 2020

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compro…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
65.2
KEV listed

CVE-2022-22536

Published Feb 9, 2022

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling an…

CVSS 10.0 · Critical
evidence mentions
11
Buzz score
64.3
KEV listed