Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SAP_SE — Vulnerabilities & Security Advisories 527

Browse all 527 CVE security advisories affecting SAP_SE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SAP SE operates as a global leader in enterprise application software, primarily providing ERP solutions that manage complex business processes, supply chains, and human resources for large organizations. This extensive attack surface has resulted in 527 recorded CVEs, reflecting the critical nature of its infrastructure. Historically, vulnerabilities within SAP systems frequently involve remote code execution, SQL injection, and cross-site scripting, often stemming from complex integrations and legacy components. Privilege escalation remains a significant concern, allowing unauthorized users to gain administrative access. While SAP maintains rigorous security protocols, past incidents highlight risks associated with default configurations and unpatched middleware. The company actively issues security patches, yet the sheer volume of disclosed flaws underscores the challenges of securing highly interconnected, mission-critical enterprise environments against sophisticated cyber threats.

CVE IDTitleCVSSSeverityPublished
CVE-2024-47593 Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP 4.3 Medium2024-11-12
CVE-2024-47592 Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application) — SAP NetWeaver Application Server Java (Logon Application)CWE-307 5.3 Medium2024-11-12
CVE-2024-47590 Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher — SAP Web DispatcherCWE-791 8.8 High2024-11-12
CVE-2024-47588 Information Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager) — SAP NetWeaver Java (Software Update Manager)CWE-522 4.7 Medium2024-11-12
CVE-2024-47587 Missing authorization check in SAP Cash Management (Cash Operations) — SAP Cash Management (Cash Operations)CWE-862 3.5 Low2024-11-12
CVE-2024-47586 NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-476 5.3 Medium2024-11-12
CVE-2024-42372 Missing Authorization check in SAP NetWeaver AS Java (System Landscape Directory) — SAP NetWeaver AS Java (System Landscape Directory)CWE-862 6.5 Medium2024-11-12
CVE-2024-47594 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC) — SAP NetWeaver Enterprise Portal (KMC)CWE-79 5.4 Medium2024-10-08
CVE-2024-45282 HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements) — SAP S/4 HANA (Manage Bank Statements)CWE-650 4.3 Medium2024-10-08
CVE-2024-45278 Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice — SAP Commerce BackofficeCWE-79 5.4 Medium2024-10-08
CVE-2024-45277 Prototype Pollution vulnerability in SAP HANA Client — SAP HANA ClientCWE-1321 4.3 Medium2024-10-08
CVE-2024-37179 Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) — SAP BusinessObjects Business Intelligence Platform (Web Intelligence)CWE-434 7.7 High2024-10-08
CVE-2024-45285 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 5.4 Medium2024-09-10
CVE-2024-45284 Missing authorization check in SAP Student Life Cycle Management (SLcM) — SAP Student Life Cycle Management (SLcM)CWE-862 2.4 Low2024-09-10
CVE-2024-45283 Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service) — SAP NetWeaver AS for Java (Destination Service)CWE-256 6.0 Medium2024-09-10
CVE-2024-45281 DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-426 5.8 Medium2024-09-10
CVE-2024-45280 Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application) — SAP NetWeaver AS Java (Logon Application)CWE-79 4.8 Medium2024-09-10
CVE-2024-45279 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP (CRM Blueprint Application Builder Panel) — SAP NetWeaver Application Server for ABAP (CRM Blueprint Application Builder Panel)CWE-79 6.1 Medium2024-09-10
CVE-2024-44121 Information Disclosure in SAP S/4 HANA (Statutory Reports) — SAP S/4 HANA (Statutory Reports)CWE-213 4.3 Medium2024-09-10
CVE-2024-44120 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal — SAP NetWeaver Enterprise PortalCWE-79 4.7 Medium2024-09-10
CVE-2024-44117 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 5.4 Medium2024-09-10
CVE-2024-44112 Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution) — SAP for Oil & GasCWE-862 4.3 Medium2024-09-10
CVE-2024-41728 Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 2.7 Low2024-09-10
CVE-2024-45286 Missing Authorization check in SAP Production and Revenue Accounting (Tobin interface) — SAP Production and Revenue Accounting (Tobin interface)CWE-862 6.5 Medium2024-09-10
CVE-2024-44116 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 4.3 Medium2024-09-10
CVE-2024-44115 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 4.3 Medium2024-09-10
CVE-2024-44114 Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-863 2.0 Low2024-09-10
CVE-2024-44113 Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer) — SAP Business Warehouse (BEx Analyzer)CWE-359 4.3 Medium2024-09-10
CVE-2024-42380 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 4.3 Medium2024-09-10
CVE-2024-42378 Cross-Site Scripting (XSS) in eProcurement on S/4HANA — SAP S/4HANA eProcurementCWE-79 6.1 Medium2024-09-10

This page lists every published CVE security advisory associated with SAP_SE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.