Sap Se
50 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-34265
CRITICAL 9.8
Sap Netweaver And Abap Platform — SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG pro…
2026-08-11
CVE-2026-40130
MEDIUM 5.3
Sapsprint Service — SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenti…
2026-08-11
CVE-2026-44758
CRITICAL 9.1
Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit special…
2026-08-11
CVE-2026-44762
LOW 3.7
Sap Data Services Management Console — SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration a…
2026-08-11
CVE-2026-44763
HIGH 7.6
Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path …
2026-08-11
CVE-2026-44764
HIGH 7.3
Sap Manufacturing Integration And Intelligence — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unaut…
2026-08-11
CVE-2026-44765
HIGH 7.3
Sap Manufacturing Integration And Intelligence — Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unaut…
2026-08-11
CVE-2026-58230
HIGH 7
Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthent…
2026-08-11
CVE-2026-58231
CRITICAL 10
Sap Commerce Cloud (Data Hub Adapter) — SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit spec…
2026-08-11
CVE-2026-58235
MEDIUM 6.3
Sap Netweaver As Java (Adobe Document Services) — SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and dat…
2026-08-11
CVE-2026-58236
MEDIUM 5.5
Sap Netweaver Application Server Abap And Abap Platform — SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missi…
2026-08-11
CVE-2026-58237
MEDIUM 5.9
Sap Business Ai Platform (Approuter) — WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attac…
2026-08-11
CVE-2026-58238
MEDIUM 5.9
Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated atta…
2026-08-11
CVE-2026-58239
LOW 3.7
Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker c…
2026-08-11
CVE-2026-58241
MEDIUM 4.2
Sap Netweaver And Abap Platform (Change And Transport System Customer Transport Integration Wizard — SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a…
2026-08-11
CVE-2026-58243
HIGH 8.8
Sap Abap Developer Tools — SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing…
2026-08-11
CVE-2026-58244
MEDIUM 4.3
Sap Manufacturing Integration And Intelligence — SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain…
2026-08-11
CVE-2026-58245
LOW 3.8
Sap Advanced Planning And Optimization (Model Mix Planning) — SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source …
2026-08-11
CVE-2026-58247
MEDIUM 5.3
Sap Abap Platform — SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component.…
2026-08-11
CVE-2026-58248
MEDIUM 6.5
Sap Businessobjects Business Intelligence — SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to uplo…
2026-08-11
CVE-2026-66760
MEDIUM 6.4
Sap Business Ai Platform (Approuter) — SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low …
2026-08-11
CVE-2026-66761
MEDIUM 4.3
Sap Business Ai Platform (Approuter) — SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileg…
2026-08-11
CVE-2026-66763
HIGH 7.9
Sap Businessobjects Business Intelligence Platform (Central Management Server) — SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user o…
2026-08-11
CVE-2026-66764
MEDIUM 4.3
Sap S/4 Hana (Reprocess Bank Statement Items) — Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenti…
2026-08-11
CVE-2026-66770
MEDIUM 6.3
Sap Social Intelligence — Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inj…
2026-08-11
CVE-2026-66771
MEDIUM 6.1
Sapui5 — SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted …
2026-08-11
CVE-2026-66772
MEDIUM 4.3
Sap Businessobjects Business Intelligence Platform (Admin Tools) — SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization ch…
2026-08-11
CVE-2026-66773
MEDIUM 5.9
Odata — A malicious or compromised OData service could disclose sensitive authentication information and inject untrus…
2026-08-11
CVE-2026-66774
LOW 3.7
Sap Business Ai Platform (Approuter) — SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exp…
2026-08-11
CVE-2026-66775
MEDIUM 4.3
Sap Business Ai Platform (Approuter) — SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An…
2026-08-11
CVE-2026-66776
MEDIUM 5.9
Sap Business Ai Platform (Approuter) — SAP Approuter does not consistently enforce integrity verification on certain session-related request headers …
2026-08-11
CVE-2026-66777
MEDIUM 5.9
Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend desti…
2026-08-11
CVE-2026-66778
MEDIUM 5.3
Sap Business Ai Platform (Approuter) — SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal com…
2026-08-11
CVE-2026-66779
MEDIUM 6.3
Sap Netweaver Application Server Abap — Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated a…
2026-08-11
CVE-2026-58246
MEDIUM 4.3
Sap Netweaver Application Server For Abap — SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information in…
2026-07-28
CVE-2026-0487
HIGH 8.4
Saprouter On Microsoft Windows — SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untruste…
2026-07-14
CVE-2026-27690
CRITICAL 9.1
Sap Approuter — Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a spec…
2026-07-14
CVE-2026-44745
HIGH 8.1
Sap Approuter — SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain c…
2026-07-14
CVE-2026-44747
CRITICAL 9.9
Sap Netweaver Application Server Abap — SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory ma…
2026-07-14
CVE-2026-44752
HIGH 8.2
Sap Netweaver Application Server Java(Configuration Wizard) — SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript throug…
2026-07-14
CVE-2026-44753
LOW 3.7
Sap Hana Extended Application Services Classic Model (User Self Service) — SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests …
2026-07-14
CVE-2026-44759
MEDIUM 6.1
Sap Netweaver Enterprise Portal — SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL para…
2026-07-14
CVE-2026-44760
MEDIUM 4.7
Sap Netweaver Application Server Abap (Applications Based On Business Server Pages) — Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SA…
2026-07-14
CVE-2026-44761
CRITICAL 9.1
Sap Commerce Cloud — SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating…
2026-07-14
CVE-2026-44767
MEDIUM 6.1
@Ui5/Webcomponents Base — setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cros…
2026-07-14
CVE-2026-44768
MEDIUM 4.1
Sap Crm (Webclient Ui) — SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the applicat…
2026-07-14
CVE-2026-44769
MEDIUM 5.5
Sap S/4hana Project Management (Ppm Pro) — SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafte…
2026-07-14
CVE-2026-44770
MEDIUM 4.3
Sap S/4 Hana (Create Single Payment) — SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restric…
2026-07-14
CVE-2026-44771
MEDIUM 4.3
Sap S/4hana (Draft Operation) — SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restr…
2026-07-14
CVE-2026-58233
HIGH 7.6
Sap Change And Transport System Attach Tool (Ctsattach) — SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially…
2026-07-14