Browse all 527 CVE security advisories affecting SAP_SE. AI-powered Chinese analysis, POCs, and references for each vulnerability.
SAP SE operates as a global leader in enterprise application software, primarily providing ERP solutions that manage complex business processes, supply chains, and human resources for large organizations. This extensive attack surface has resulted in 527 recorded CVEs, reflecting the critical nature of its infrastructure. Historically, vulnerabilities within SAP systems frequently involve remote code execution, SQL injection, and cross-site scripting, often stemming from complex integrations and legacy components. Privilege escalation remains a significant concern, allowing unauthorized users to gain administrative access. While SAP maintains rigorous security protocols, past incidents highlight risks associated with default configurations and unpatched middleware. The company actively issues security patches, yet the sheer volume of disclosed flaws underscores the challenges of securing highly interconnected, mission-critical enterprise environments against sophisticated cyber threats.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-24875 | SameSite Defense in Depth not applied for some cookies in SAP Commerce — SAP CommerceCWE-352 | 6.8 | Medium | 2025-02-11 |
| CVE-2024-41733 | Information Disclosure Vulnerability in SAP Commerce — SAP CommerceCWE-200 | 5.3 | Medium | 2024-08-13 |
| CVE-2024-39597 | [CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce — SAP CommerceCWE-285 | 7.2 | High | 2024-07-09 |
| CVE-2023-39439 | SAP Commerce accepts empty passphrases. — SAP CommerceCWE-258 | 8.8 | High | 2023-08-08 |
This page lists every published CVE security advisory associated with SAP_SE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.