SAP SE

First CVE: Dec 12, 2017Active for: 9 years
1,510
CVEs Published
More CVEs Published than 92% of tracked CNAs
151.0
Avg CVEs / Year
More Avg CVEs / Year than 92% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
0.5%
In CISA KEV
Higher KEV Rate than 85% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by SAP SE as a CNA, 78.9% affect products that SAP SE develops as a vendor.

78.9%
21.1%
Self-reported: 1,192Third-party: 318

Of all the CVEs published that affect products developed by SAP SE, 75.4% are self-published by SAP SE as a CNA.

75.4%
24.6%
Self-published: 1,192Published by other CNAs: 388

Trends Over Time

The number and severity of CVEs published by SAP SE over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2017
8 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by SAP SE as a CNA, regardless of affected vendor or product.

1,510 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha
Apr 24, 20259.898YESYES
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and
Feb 9, 202210.098YESYES
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t
Jul 14, 202010.098YESYES
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete comprom
Mar 10, 20209.898YESYES
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file ov
Sep 14, 20218.882YESNO
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to p
Mar 1, 20186.682YESYES
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40,
Sep 15, 20219.978NOYES
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint
Aug 13, 20249.873NONO
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a targe
Aug 14, 20199.873YESNO
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a
May 13, 20259.172YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,510 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local180 (11.9%)
Network1,299 (86.0%)
Unknown0 (0.0%)
Physical6 (0.4%)
Adjacent Network25 (1.7%)
Attack Complexity
Low1,428 (94.6%)
High82 (5.4%)
Unknown0 (0.0%)
User Interaction
None961 (63.6%)
Unknown0 (0.0%)
Required549 (36.4%)
Privileges Required
Low598 (39.6%)
High188 (12.5%)
None724 (47.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1510 CVEs).

CISA KEV
8 CVEs
0.5% of CVEs· 85th percentile
Metasploit
5 CVEs
0.3% of CVEs· 80th percentile
Nuclei
10 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
4 CVEs
0.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by SAP SE as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SAP SE as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs