Vendor
SAP SE doing business as SAP, is a German multinational software company based in Walldorf, Baden-Württemberg, that is the world's largest vendor of enterprise software.
Founded 1972
Products
143
CVEs
344
Across products
648
Status
Private
Products
143- 123 CVEs
- 28 CVEs
- 26 CVEs
- 26 CVEs
- 24 CVEs
- 21 CVEs
- 21 CVEs
- 19 CVEs
- 17 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 11 CVEs
- 11 CVEs
- 10 CVEs
- 9 CVEs
- 7 CVEs
- 6 CVEs
- 6 CVEs
- 6 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- + 113 more — see CVE list below for full coverage.
Recent CVEs
344| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2016-2386 | Cri | 0.82 | 9.8 | 0.44 | KEV | Feb 16, 2016 | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079. |
| CVE-2010-5326 | Cri | 0.78 | 10.0 | 0.13 | KEV | May 13, 2016 | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack. |
| CVE-2016-3976 | Hig | 0.70 | 7.5 | 0.76 | KEV | Apr 7, 2016 | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971. |
| CVE-2017-12637 | Hig | 0.68 | 7.5 | 0.93 | KEV | Aug 7, 2017 | Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657. |
| CVE-2016-1928 | Cri | 0.67 | 9.8 | 0.37 | Jan 20, 2016 | Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security Note 2241978. | |
| CVE-2017-16684 | Cri | 0.64 | 9.8 | 0.01 | Dec 12, 2017 | SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionalities that require user identity. | |
| CVE-2017-15295 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2017 | Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064. | |
| CVE-2017-15293 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2017 | Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064. | |
| CVE-2017-11459 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2017 | SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592. | |
| CVE-2016-6143 | Cri | 0.64 | 9.8 | 0.06 | Apr 13, 2017 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | |
| CVE-2017-7691 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2017 | A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592. | |
| CVE-2017-6950 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2017 | SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616. | |
| CVE-2016-3974 | Cri | 0.63 | 9.1 | 0.14 | Apr 7, 2016 | XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994. | |
| CVE-2016-1929 | Cri | 0.61 | 9.3 | 0.01 | Jan 20, 2016 | The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified debug function, aka SAP Security Note 2241978. | |
| CVE-2016-9563 | Med | 0.59 | 6.5 | 0.59 | KEV | Nov 23, 2016 | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. |
| CVE-2016-7435 | Cri | 0.59 | 9.1 | 0.01 | Oct 5, 2016 | The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344. | |
| CVE-2015-8753 | Cri | 0.59 | 9.1 | 0.00 | Jan 8, 2016 | SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905. | |
| CVE-2016-2389 | Hig | 0.58 | 7.5 | 0.84 | Feb 16, 2016 | Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978. | |
| CVE-2017-16689 | Hig | 0.57 | 8.8 | 0.00 | Dec 12, 2017 | A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL from 7.21 to 7.22, 7.45, 7.49, can be established to a different client or a different user on the same system, although no explicit Trusted/Trusting Relation to the same system has been defined. | |
| CVE-2017-15296 | Hig | 0.57 | 8.8 | 0.00 | Oct 16, 2017 | The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. |