Sap
60 known vulnerabilities
Top Products
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft
Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated att
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP reques
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when cli
Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages),
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker w
SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripti
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters
SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, res
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator wit
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car
Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could in
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform backgrou
The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert m
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficientl
SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted en
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function modul
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authen
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause t
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker c
Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a m
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthen
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attack
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the fu
SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switc
Frequently Asked Questions
How many CVEs affect Sap?
Sap has 60 CVE records in our database, including 8 critical and 9 high severity vulnerabilities.
What are the most severe Sap vulnerabilities?
Sap has 8 critical severity (CVSS 9.0+) and 9 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Sap vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Sap products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Sap Vulnerabilities
CyberStrike scans your infrastructure for Sap vulnerabilities and provides real-time remediation guidance.
Get Started