← Browse

Sap Se

50 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-34265 CRITICAL 9.8 Sap Netweaver And Abap Platform — SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG pro… 2026-08-11 CVE-2026-40130 MEDIUM 5.3 Sapsprint Service — SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenti… 2026-08-11 CVE-2026-44758 CRITICAL 9.1 Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit special… 2026-08-11 CVE-2026-44762 LOW 3.7 Sap Data Services Management Console — SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration a… 2026-08-11 CVE-2026-44763 HIGH 7.6 Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path … 2026-08-11 CVE-2026-44764 HIGH 7.3 Sap Manufacturing Integration And Intelligence — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unaut… 2026-08-11 CVE-2026-44765 HIGH 7.3 Sap Manufacturing Integration And Intelligence — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unaut… 2026-08-11 CVE-2026-58230 HIGH 7 Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthent… 2026-08-11 CVE-2026-58231 CRITICAL 10 Sap Commerce Cloud (Data Hub Adapter) — SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit spec… 2026-08-11 CVE-2026-58235 MEDIUM 6.3 Sap Netweaver As Java (Adobe Document Services) — SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and dat… 2026-08-11 CVE-2026-58236 MEDIUM 5.5 Sap Netweaver Application Server Abap And Abap Platform — SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missi… 2026-08-11 CVE-2026-58237 MEDIUM 5.9 Sap Business Ai Platform (Approuter) — WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attac… 2026-08-11 CVE-2026-58238 MEDIUM 5.9 Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated atta… 2026-08-11 CVE-2026-58239 LOW 3.7 Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker c… 2026-08-11 CVE-2026-58241 MEDIUM 4.2 Sap Netweaver And Abap Platform (Change And Transport System Customer Transport Integration Wizard — SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a… 2026-08-11 CVE-2026-58243 HIGH 8.8 Sap Abap Developer Tools — SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing… 2026-08-11 CVE-2026-58244 MEDIUM 4.3 Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain… 2026-08-11 CVE-2026-58245 LOW 3.8 Sap Advanced Planning And Optimization (Model Mix Planning) — SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source … 2026-08-11 CVE-2026-58247 MEDIUM 5.3 Sap Abap Platform — SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component.… 2026-08-11 CVE-2026-58248 MEDIUM 6.5 Sap Businessobjects Business Intelligence — SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to uplo… 2026-08-11 CVE-2026-66760 MEDIUM 6.4 Sap Business Ai Platform (Approuter) — SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low … 2026-08-11 CVE-2026-66761 MEDIUM 4.3 Sap Business Ai Platform (Approuter) — SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileg… 2026-08-11 CVE-2026-66763 HIGH 7.9 Sap Businessobjects Business Intelligence Platform (Central Management Server) — SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user o… 2026-08-11 CVE-2026-66764 MEDIUM 4.3 Sap S/4 Hana (Reprocess Bank Statement Items) — Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenti… 2026-08-11 CVE-2026-66770 MEDIUM 6.3 Sap Social Intelligence — Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inj… 2026-08-11 CVE-2026-66771 MEDIUM 6.1 Sapui5 — SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted … 2026-08-11 CVE-2026-66772 MEDIUM 4.3 Sap Businessobjects Business Intelligence Platform (Admin Tools) — SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization ch… 2026-08-11 CVE-2026-66773 MEDIUM 5.9 Odata — A malicious or compromised OData service could disclose sensitive authentication information and inject untrus… 2026-08-11 CVE-2026-66774 LOW 3.7 Sap Business Ai Platform (Approuter) — SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exp… 2026-08-11 CVE-2026-66775 MEDIUM 4.3 Sap Business Ai Platform (Approuter) — SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An… 2026-08-11 CVE-2026-66776 MEDIUM 5.9 Sap Business Ai Platform (Approuter) — SAP Approuter does not consistently enforce integrity verification on certain session-related request headers … 2026-08-11 CVE-2026-66777 MEDIUM 5.9 Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend desti… 2026-08-11 CVE-2026-66778 MEDIUM 5.3 Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal com… 2026-08-11 CVE-2026-66779 MEDIUM 6.3 Sap Netweaver Application Server Abap — Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated a… 2026-08-11 CVE-2026-58246 MEDIUM 4.3 Sap Netweaver Application Server For Abap — SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information in… 2026-07-28 CVE-2026-0487 HIGH 8.4 Saprouter On Microsoft Windows — SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untruste… 2026-07-14 CVE-2026-27690 CRITICAL 9.1 Sap Approuter — Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a spec… 2026-07-14 CVE-2026-44745 HIGH 8.1 Sap Approuter — SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain c… 2026-07-14 CVE-2026-44747 CRITICAL 9.9 Sap Netweaver Application Server Abap — SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory ma… 2026-07-14 CVE-2026-44752 HIGH 8.2 Sap Netweaver Application Server Java(Configuration Wizard) — SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript throug… 2026-07-14 CVE-2026-44753 LOW 3.7 Sap Hana Extended Application Services Classic Model (User Self Service) — SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests … 2026-07-14 CVE-2026-44759 MEDIUM 6.1 Sap Netweaver Enterprise Portal — SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL para… 2026-07-14 CVE-2026-44760 MEDIUM 4.7 Sap Netweaver Application Server Abap (Applications Based On Business Server Pages) — Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SA… 2026-07-14 CVE-2026-44761 CRITICAL 9.1 Sap Commerce Cloud — SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating… 2026-07-14 CVE-2026-44767 MEDIUM 6.1 @Ui5/Webcomponents Base — setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cros… 2026-07-14 CVE-2026-44768 MEDIUM 4.1 Sap Crm (Webclient Ui) — SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the applicat… 2026-07-14 CVE-2026-44769 MEDIUM 5.5 Sap S/4hana Project Management (Ppm Pro) — SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafte… 2026-07-14 CVE-2026-44770 MEDIUM 4.3 Sap S/4 Hana (Create Single Payment) — SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restric… 2026-07-14 CVE-2026-44771 MEDIUM 4.3 Sap S/4hana (Draft Operation) — SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restr… 2026-07-14 CVE-2026-58233 HIGH 7.6 Sap Change And Transport System Attach Tool (Ctsattach) — SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially… 2026-07-14