Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

SAP

Vulnerabilities and patches across SAP's enterprise stack — NetWeaver Application Server (Java and ABAP), S/4HANA, Business Technology Platform, AppRouter, and Commerce Cloud — including the monthly SAP Security Patch Day cycle.

18 CVEs3 articlesRSS
CVEs
CVE-2026-58231
[ CRITICAL ]CVSS 10.0EPSS 1.7%patched

SAP Commerce Cloud Data Hub Adapter Unauthenticated RCE

Insufficient authorization checks and input validation in SAP Commerce Cloud Data Hub Adapter allow unauthenticated remote code execution. CVSS 10.0.

SAP / Commerce Cloud (Data Hub Adapter)
CVE-2026-27690
[ CRITICAL ]CVSS 9.1EPSS 0.7%patched

SAP AppRouter HTTP request smuggling in Node.js middleware

Unauthenticated HTTP request smuggling in SAP AppRouter — the Node.js middleware fronting Business Technology Platform. NVD scored it 9.1. A crafted request can desynchronize the request-response pipeline, exposing other users' responses and knocking the service offline.

SAP / AppRouter (Node.js middleware for SAP Business Technology Platform)
CVE-2026-44747
[ CRITICAL ]CVSS 9.9EPSS 0.6%patched

SAP NetWeaver AS ABAP memory-corruption via logical errors in memory management

Authenticated memory-corruption in NetWeaver Application Server ABAP that NVD scored 9.9 — a logged-in attacker can leverage logical errors in memory management to read data, modify data, or take the application down. Fixed in the SAP July 2026 Security Patch Day.

SAP / NetWeaver Application Server ABAP (see body — version details in SAP's July 2026 Security Note)
CVE-2026-44761
[ CRITICAL ]CVSS 9.1EPSS 0.5%patched

SAP Commerce Cloud ships sample OAuth2 client with publicly documented credentials

SAP Commerce Cloud retained a sample OAuth2 client whose credentials were documented in SAP Help Portal. If left unchanged, an unauthenticated attacker can use those well-known values to obtain a valid access token and read or modify tenant data via certain APIs. NVD scored 9.1.

SAP / Commerce Cloud (sample OAuth2 client shipped from documentation)
CVE-2025-42999
[ CRITICAL ]CVSS 9.1EPSS 13.9%kev

SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

SAP / NetWeaver
CVE-2025-31324
[ CRITICAL ]CVSS 10.0EPSS 99.5%kev

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

SAP / NetWeaver
CVE-2017-12637
[ HIGH ]CVSS 7.5EPSS 95.1%kev

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

SAP / NetWeaver
CVE-2019-0344
[ CRITICAL ]CVSS 9.8EPSS 7.1%kev

SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

SAP / Commerce Cloud
CVE-2022-22536
[ CRITICAL ]CVSS 10.0EPSS 97.9%kev

SAP Multiple Products HTTP Request Smuggling Vulnerability

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

SAP / Multiple Products
CVE-2016-2386
[ CRITICAL ]CVSS 9.8EPSS 71.1%kev

SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SAP / NetWeaver
CVE-2016-2388
[ MEDIUM ]CVSS 5.3EPSS 51.6%kev

SAP NetWeaver Information Disclosure Vulnerability

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

SAP / NetWeaver
CVE-2021-38163
[ CRITICAL ]CVSS 9.9EPSS 36.0%kev

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

SAP / NetWeaver
CVE-2010-5326
[ CRITICAL ]CVSS 10.0EPSS 17.4%kev

SAP NetWeaver Remote Code Execution Vulnerability

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

SAP / NetWeaver
CVE-2016-3976
[ HIGH ]CVSS 7.5EPSS 46.6%kev

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

SAP / NetWeaver
CVE-2016-9563
[ MEDIUM ]CVSS 6.5EPSS 23.8%kev

SAP NetWeaver XML External Entity (XXE) Vulnerability

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

SAP / NetWeaver
CVE-2018-2380
[ MEDIUM ]CVSS 6.6EPSS 28.9%kev

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

SAP / Customer Relationship Management (CRM)
CVE-2020-6207
[ CRITICAL ]CVSS 9.8EPSS 98.3%kev

SAP Solution Manager Missing Authentication for Critical Function Vulnerability

SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.

SAP / Solution Manager
CVE-2020-6287
[ CRITICAL ]CVSS 10.0EPSS 94.7%kev

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

SAP / NetWeaver
Articles