Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SAP_SE — Vulnerabilities & Security Advisories 527

Browse all 527 CVE security advisories affecting SAP_SE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SAP SE operates as a global leader in enterprise application software, primarily providing ERP solutions that manage complex business processes, supply chains, and human resources for large organizations. This extensive attack surface has resulted in 527 recorded CVEs, reflecting the critical nature of its infrastructure. Historically, vulnerabilities within SAP systems frequently involve remote code execution, SQL injection, and cross-site scripting, often stemming from complex integrations and legacy components. Privilege escalation remains a significant concern, allowing unauthorized users to gain administrative access. While SAP maintains rigorous security protocols, past incidents highlight risks associated with default configurations and unpatched middleware. The company actively issues security patches, yet the sheer volume of disclosed flaws underscores the challenges of securing highly interconnected, mission-critical enterprise environments against sophisticated cyber threats.

CVE IDTitleCVSSSeverityPublished
CVE-2024-42371 Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-862 5.4 Medium2024-09-10
CVE-2024-41729 Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer) — SAP NetWeaver BW (BEx Analyzer)CWE-359 4.3 Medium2024-09-10
CVE-2024-39591 Missing Authorization check in SAP Document Builder — SAP Document BuilderCWE-862 4.3 Medium2024-08-13
CVE-2024-42373 Missing Authorization Check in SAP Student Life Cycle Management (SLcM) — SAP Student Life Cycle Management (SLcM)CWE-862 4.3 Medium2024-08-13
CVE-2024-41734 Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP PlatformCWE-862 4.3 Medium2024-08-13
CVE-2024-41736 Information Disclosure vulnerability in SAP Permit to Work — SAP Permit to WorkCWE-200 4.3 Medium2024-08-13
CVE-2024-41731 Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-434 3.1 Low2024-08-13
CVE-2024-28166 Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-434 3.7 Low2024-08-13
CVE-2024-42375 Multiple Unrestricted File Upload vulnerabilities in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-434 4.3 Medium2024-08-13
CVE-2024-41732 Improper Access Control in SAP Netweaver Application Server ABAP — SAP NetWeaver Application Server ABAPCWE-284 4.7 Medium2024-08-13
CVE-2024-41737 Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management) — SAP CRM ABAP (Insights Management)CWE-918 5.0 Medium2024-08-13
CVE-2024-41733 Information Disclosure Vulnerability in SAP Commerce — SAP CommerceCWE-200 5.3 Medium2024-08-13
CVE-2024-41735 Cross-Site Scripting (XSS) vulnerability in SAP Commerce Backoffice — SAP Commerce BackofficeCWE-79 5.4 Medium2024-08-13
CVE-2024-33005 Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server — SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content ServerCWE-862 6.3 Medium2024-08-13
CVE-2024-42377 Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework — SAP Shared Service FrameworkCWE-862 4.3 Medium2024-08-13
CVE-2024-42376 Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework — SAP Shared Service FrameworkCWE-862 6.5 Medium2024-08-13
CVE-2024-33003 Information Disclosure Vulnerability in SAP Commerce Cloud — SAP Commerce CloudCWE-200 7.4 High2024-08-13
CVE-2024-42374 XML injection in SAP BEx Web Java Runtime Export Web Service — SAP BEx Web Java Runtime Export Web ServiceCWE-91 8.2 High2024-08-13
CVE-2024-41730 Missing Authentication check in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-862 9.8 Critical2024-08-13
CVE-2024-34692 [CVE-2024-34692] Unrestricted File upload vulnerability in SAP Enable Now — SAP Enable NowCWE-434 3.3 Low2024-07-09
CVE-2024-37180 [CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-200 4.1 Medium2024-07-09
CVE-2024-39596 [CVE-2024-39596] Missing Authorization check vulnerability in SAP Enable Now — SAP Enable NowCWE-862 4.3 Medium2024-07-09
CVE-2024-39599 [CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-693 4.7 Medium2024-07-09
CVE-2024-37171 [CVE-2024-37171] Server-Side Request Forgery (SSRF) in SAP Transportation Management (Collaboration Portal) — SAP Transportation Management (Collaboration Portal)CWE-918 5.0 Medium2024-07-09
CVE-2024-39600 [CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows — SAP GUI for WindowsCWE-200 5.0 Medium2024-07-09
CVE-2024-34689 [CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services) — SAP Business Workflow (WebFlow Services)CWE-918 5.0 Medium2024-07-09
CVE-2024-37172 [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management) — SAP S/4HANA Finance (Advanced Payment Management)CWE-862 5.4 Medium2024-07-09
CVE-2024-39595 [CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation — SAP Business Warehouse - Business Planning and SimulationCWE-79 5.4 Medium2024-07-09
CVE-2024-39594 [CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation — SAP Business Warehouse - Business Planning and SimulationCWE-79 6.1 Medium2024-07-09
CVE-2024-37175 [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI) — SAP CRM WebClient UICWE-862 4.3 Medium2024-07-09

This page lists every published CVE security advisory associated with SAP_SE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.