SAP SE
First CVE: Dec 12, 2017Active for: 9 years
1,510
CVEs Published
More CVEs Published than 92% of tracked CNAs
151.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
0.5%
In CISA KEV
Higher KEV Rate than 85% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by SAP SE as a CNA, 78.9% affect products that SAP SE develops as a vendor.
78.9%
21.1%
Self-reported: 1,192Third-party: 318
Of all the CVEs published that affect products developed by SAP SE, 75.4% are self-published by SAP SE as a CNA.
75.4%
24.6%
Self-published: 1,192Published by other CNAs: 388
Trends Over Time
The number and severity of CVEs published by SAP SE over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2017
8 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by SAP SE as a CNA, regardless of affected vendor or product.
1,510 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31324CRITICAL SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha | Apr 24, 2025 | 9.8 | 98 | YES | YES |
CVE-2022-22536CRITICAL SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and | Feb 9, 2022 | 10.0 | 98 | YES | YES |
CVE-2020-6287CRITICAL SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t | Jul 14, 2020 | 10.0 | 98 | YES | YES |
CVE-2020-6207CRITICAL SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete comprom | Mar 10, 2020 | 9.8 | 98 | YES | YES |
CVE-2021-38163HIGH SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file ov | Sep 14, 2021 | 8.8 | 82 | YES | NO |
CVE-2018-2380MEDIUM SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to p | Mar 1, 2018 | 6.6 | 82 | YES | YES |
CVE-2021-33690CRITICAL Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, | Sep 15, 2021 | 9.9 | 78 | NO | YES |
CVE-2024-41730CRITICAL In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a logon token using a REST endpoint | Aug 13, 2024 | 9.8 | 73 | NO | NO |
CVE-2019-0344CRITICAL Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a targe | Aug 14, 2019 | 9.8 | 73 | YES | NO |
CVE-2025-42999CRITICAL SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a | May 13, 2025 | 9.1 | 72 | YES | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,510 CVEs
60%
28%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local180 (11.9%)
Network1,299 (86.0%)
Unknown0 (0.0%)
Physical6 (0.4%)
Adjacent Network25 (1.7%)
Attack Complexity
Low1,428 (94.6%)
High82 (5.4%)
Unknown0 (0.0%)
User Interaction
None961 (63.6%)
Unknown0 (0.0%)
Required549 (36.4%)
Privileges Required
Low598 (39.6%)
High188 (12.5%)
None724 (47.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1510 CVEs).
CISA KEV
8 CVEs
0.5% of CVEs· 85th percentile
Metasploit
5 CVEs
0.3% of CVEs· 80th percentile
Nuclei
10 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
4 CVEs
0.3% of CVEs· 74th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by SAP SE as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SAP SE as a CNA — matched by CVE ID, not by organization name.