Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

SAP SE

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 1,580
54.4
VTI Score
TOP TARGET

SAP SE's vulnerability footprint spans a large portfolio of enterprise resource planning, business intelligence, and application server products that are deeply embedded in mission-critical business operations across a broad range of organizations. Vulnerabilities affecting the vendor skew toward a meaningful share of serious-severity outcomes and recur across flagship products such as NetWeaver, BusinessObjects Business Intelligence Platform, and the 3D Visual Enterprise Viewer through weakness classes including cross-site scripting, missing authorization controls, and memory-buffer handling issues that are characteristic of large, integration-heavy enterprise middleware. The exposure reflects both the web-facing and internal-service roles these products occupy and the parsing and access-control demands of complex business-process platforms. Defenders should prioritize tracking SAP's coordinated patch cycles and inventory affected applications across their enterprise landscape; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,580
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by SAP SE over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
May 14, 2026
72 days ago

Self-Reporting Analysis

Of all the CVEs published by SAP SE as a CNA, 78.9% affect products that SAP SE develops as a vendor.

78.9%
21.1%
Self-reported: 1,192 (78.9%)
Third-party: 318 (21.1%)

Of all the CVEs published that affect products developed by SAP SE, 75.4% are self-published by SAP SE as a CNA.

75.4%
24.6%
Self-published: 1,192 (75.4%)
Other CNAs: 388 (24.6%)

Products(429 total)

Top CVEs

Signals from CVEs in this vendor scope (1580 CVEs).

1,580 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-31324CRITICAL
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha
Apr 24, 20259.898YESYES
CVE-2022-22536CRITICAL
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and
Feb 9, 202210.098YESYES
CVE-2020-6287CRITICAL
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t
Jul 14, 202010.098YESYES
CVE-2020-6207CRITICAL
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete comprom
Mar 10, 20209.898YESYES
CVE-2017-12637HIGH
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary file
Aug 7, 20177.596YESYES
CVE-2016-2386CRITICAL
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security
Feb 16, 20169.895YESYES
CVE-2010-0219HIGH
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, whi
Oct 18, 201010.092NOYES
CVE-2016-3976HIGH
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter t
Apr 7, 20167.587YESYES
CVE-2016-2388MEDIUM
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 225
Feb 16, 20165.387YESYES
CVE-2008-0244HIGH
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands,
Jan 12, 200810.085NOYES
View all 1,580 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,580 CVEs
58%
32%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local167 (10.6%)
Network1,110 (70.3%)
Unknown281 (17.8%)
Physical5 (0.3%)
Adjacent Network17 (1.1%)
Attack Complexity
Low1,260 (79.7%)
High39 (2.5%)
Unknown281 (17.8%)
User Interaction
None812 (51.4%)
Unknown281 (17.8%)
Required487 (30.8%)
Privileges Required
Low465 (29.4%)
High122 (7.7%)
None712 (45.1%)
Unknown281 (17.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (1580 CVEs).

CISA KEV
14 CVEs
0.9% of CVEs· 99th percentile
Metasploit
17 CVEs
1.1% of CVEs· 97th percentile
Nuclei
14 CVEs
0.9% of CVEs· 95th percentile
ExploitDB
57 CVEs
3.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by SAP SE.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by SAP SE — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For SAP SE's Products

View all 6 CNAs →

Top CWEs