Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SAP_SE — Vulnerabilities & Security Advisories 527

Browse all 527 CVE security advisories affecting SAP_SE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SAP SE operates as a global leader in enterprise application software, primarily providing ERP solutions that manage complex business processes, supply chains, and human resources for large organizations. This extensive attack surface has resulted in 527 recorded CVEs, reflecting the critical nature of its infrastructure. Historically, vulnerabilities within SAP systems frequently involve remote code execution, SQL injection, and cross-site scripting, often stemming from complex integrations and legacy components. Privilege escalation remains a significant concern, allowing unauthorized users to gain administrative access. While SAP maintains rigorous security protocols, past incidents highlight risks associated with default configurations and unpatched middleware. The company actively issues security patches, yet the sheer volume of disclosed flaws underscores the challenges of securing highly interconnected, mission-critical enterprise environments against sophisticated cyber threats.

CVE IDTitleCVSSSeverityPublished
CVE-2023-31407 Cross-Site Scripting (XSS) vulnerability in SAP Business Planning and Consolidation — SAP Business Planning and ConsolidationCWE-79 5.4 Medium2023-05-09
CVE-2023-31406 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-79 6.1 Medium2023-05-09
CVE-2023-31404 Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service) — SAP BusinessObjects Business Intelligence Platform (Central Management Service)CWE-200 5.0 Medium2023-05-09
CVE-2023-30744 Improper access control during application start-up in SAP AS NetWeaver JAVA. — SAP AS NetWeaver JAVACWE-306 8.2 High2023-05-09
CVE-2023-30743 Improper Neutralization of Input in SAPUI5 — SAPUI5CWE-79 7.1 High2023-05-09
CVE-2023-30742 Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI) — SAP CRM (WebClient UI)CWE-79 6.1 Medium2023-05-09
CVE-2023-30741 Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-79 6.1 Medium2023-05-09
CVE-2023-30740 Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence PlatformCWE-200 6.3 Medium2023-05-09
CVE-2023-29188 Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI — SAP CRM WebClient UICWE-79 5.4 Medium2023-05-09
CVE-2023-28764 Information Disclosure vulnerability in SAP BusinessObjects Platform — SAP BusinessObjects PlatformCWE-522 3.7 Low2023-05-09
CVE-2023-28762 Information Disclosure in SAP BusinessObjects Intelligence Platform — SAP BusinessObjects Intelligence PlatformCWE-200 9.1 Critical2023-05-09
CVE-2023-27499 Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML — GUI for HTMLCWE-79 6.1 Medium2023-04-11
CVE-2023-0021 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver — SAP NetWeaverCWE-79 6.1 Medium2023-03-14
CVE-2023-23858 SAP NetWeaver AS 跨站脚本漏洞 — SAP NetWeaver AS for ABAP and ABAP PlatformCWE-79 6.1 Medium2023-02-14
CVE-2023-23856 SAP BusinessObjects Business Intelligence 跨站脚本漏洞 — SAP BusinessObjects Business Intelligence (Web Intelligence UI)CWE-79 4.3 Medium2023-02-14
CVE-2023-0020 SAP BusinessObjects Business Intelligence 信息泄露漏洞 — SAP BusinessObjects Business Intelligence PlatformCWE-200 8.5 High2023-02-14
CVE-2023-0019 SAP GRC 安全漏洞 — SAP GRC (Process Control)CWE-862 6.5 Medium2023-02-14

This page lists every published CVE security advisory associated with SAP_SE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.