SAP SE's vulnerability footprint spans a large portfolio of enterprise resource planning, business intelligence, and application server products that are deeply embedded in mission-critical business operations across a broad range of organizations. Vulnerabilities affecting the vendor skew toward a meaningful share of serious-severity outcomes and recur across flagship products such as NetWeaver, BusinessObjects Business Intelligence Platform, and the 3D Visual Enterprise Viewer through weakness classes including cross-site scripting, missing authorization controls, and memory-buffer handling issues that are characteristic of large, integration-heavy enterprise middleware. The exposure reflects both the web-facing and internal-service roles these products occupy and the parsing and access-control demands of complex business-process platforms. Defenders should prioritize tracking SAP's coordinated patch cycles and inventory affected applications across their enterprise landscape; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by SAP SE over time
Of all the CVEs published by SAP SE as a CNA, 78.9% affect products that SAP SE develops as a vendor.
Of all the CVEs published that affect products developed by SAP SE, 75.4% are self-published by SAP SE as a CNA.
Signals from CVEs in this vendor scope (1580 CVEs).
1,580 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31324CRITICAL SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha | Apr 24, 2025 | 9.8 | 98 | YES | YES |
CVE-2022-22536CRITICAL SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and | Feb 9, 2022 | 10.0 | 98 | YES | YES |
CVE-2020-6287CRITICAL SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t | Jul 14, 2020 | 10.0 | 98 | YES | YES |
CVE-2020-6207CRITICAL SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete comprom | Mar 10, 2020 | 9.8 | 98 | YES | YES |
CVE-2017-12637HIGH Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary file | Aug 7, 2017 | 7.5 | 96 | YES | YES |
CVE-2016-2386CRITICAL SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security | Feb 16, 2016 | 9.8 | 95 | YES | YES |
CVE-2010-0219HIGH Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, whi | Oct 18, 2010 | 10.0 | 92 | NO | YES |
CVE-2016-3976HIGH Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter t | Apr 7, 2016 | 7.5 | 87 | YES | YES |
CVE-2016-2388MEDIUM The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 225 | Feb 16, 2016 | 5.3 | 87 | YES | YES |
CVE-2008-0244HIGH SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, | Jan 12, 2008 | 10.0 | 85 | NO | YES |
Signals from CVEs in this vendor scope (1580 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by SAP SE.
Media articles that mention a CVE ID that affects a product developed by SAP SE — matched by CVE ID, not by vendor name.