Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2025-42920

Published Sep 9, 2025

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly acc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42918

Published Sep 9, 2025

SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42911

Published Sep 9, 2025

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and opera…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42936

Published Aug 12, 2025

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated use…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42956

Published Jul 8, 2025

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42986

Published Jul 8, 2025

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), pot…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42968

Published Jul 8, 2025

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP syste…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23192

Published Jun 10, 2025

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the wo…

CVSS 8.2 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-42999

Published May 13, 2025

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to…

CVSS 9.1 · Critical
evidence mentions
11
Buzz score
64.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-30018

Published May 13, 2025

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which wh…

CVSS 8.6 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-30012

Published May 13, 2025

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload…

CVSS 10.0 · Critical
evidence mentions
6
Buzz score
39.0
Vendor/product tagsBeta · best-effort

CVE-2025-30011

Published May 13, 2025

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated att…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-30010

Published May 13, 2025

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated att…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-30009

Published May 13, 2025

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated atta…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-31324

Published Apr 24, 2025

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries th…

CVSS 10.0 · Critical
evidence mentions
39
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-25245

Published Mar 11, 2025

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-23193

Published Feb 11, 2025

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, p…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-0064

Published Feb 11, 2025

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0066

Published Jan 14, 2025

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access cont…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0063

Published Jan 14, 2025

SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0061

Published Jan 14, 2025

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an informa…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0060

Published Jan 14, 2025

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the se…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0058

Published Jan 14, 2025

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 51-75 of 1,580 CVEsPage 3 of 64