SAP SAP Enterprise Application Software

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any SAP product.

RSS Feeds for SAP security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in SAP products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by SAP Sorted by Most Security Vulnerabilities since 2018

SAP NetWeaver74 vulnerabilities

SAP Netweaver As Abap45 vulnerabilities

SAP S4hana38 vulnerabilities

SAP Solution Manager33 vulnerabilities

SAP Business One32 vulnerabilities

SAP Netweaver Abap24 vulnerabilities

SAP Businessobjects22 vulnerabilities

SAP Commerce Cloud21 vulnerabilities

SAP Enable Now15 vulnerabilities

SAP Web Dispatcher14 vulnerabilities

SAP Abap Platform13 vulnerabilities

SAP Host Agent13 vulnerabilities

SAP Hana11 vulnerabilities

SAP S4core11 vulnerabilities

SAP Financial Consolidation9 vulnerabilities

SAP Cloud Connector9 vulnerabilities

SAP Commerce9 vulnerabilities

SAP Landscape Management8 vulnerabilities

SAP Business Warehouse8 vulnerabilities

SAP S4 Hana7 vulnerabilities

SAP Hana Database7 vulnerabilities

SAP Sql Anywhere6 vulnerabilities

SAP Powerdesigner6 vulnerabilities

SAP Erp5 vulnerabilities

SAP Gui For Windows5 vulnerabilities

Sap Business Connector5 vulnerabilities

SAP Identity Management5 vulnerabilities

SAP Bw4hana5 vulnerabilities

SAP Content Server5 vulnerabilities

Sapcar4 vulnerabilities

SAP Fiori4 vulnerabilities

SAP Commoncryptolib4 vulnerabilities

SAP Diagnostics Agent4 vulnerabilities

SAP Bank Account Management2 vulnerabilities

Recent SAP Security Advisories

Advisory Title Published
2026-04-14 SAP Security Patch Day - April 2026 April 14, 2026
2026-03-11 SAP Security Patch Day - March 2026 March 11, 2026
2026-02-10 SAP Security Patch Day - February 2026 February 10, 2026
2026-01-13 SAP Security Patch Day - January 2026 January 13, 2026
2025-12-09 SAP Security Patch Day - December 2025 December 9, 2025
2025-11-11 SAP Security Patch Day - November 2025 November 11, 2025
2025-10-12 SAP Security Patch Day - October 2025 October 12, 2025
2025-09-12 SAP Security Patch Day - September 2025 September 12, 2025
2025-08-12 SAP Security Patch Day - August 2025 August 12, 2025
2025-07-12 SAP Security Patch Day - July 2025 July 12, 2025

Known Exploited SAP Vulnerabilities

The following SAP vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
SAP NetWeaver Deserialization Vulnerability SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
CVE-2025-42999 Exploit Probability: 50.3%
May 15, 2025
SAP NetWeaver Unrestricted File Upload Vulnerability SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
CVE-2025-31324 Exploit Probability: 34.1%
April 29, 2025
SAP NetWeaver Directory Traversal Vulnerability SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.
CVE-2017-12637 Exploit Probability: 93.3%
March 19, 2025
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.
CVE-2019-0344 Exploit Probability: 40.6%
September 30, 2024
SAP Multiple Products HTTP Request Smuggling Vulnerability SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.
CVE-2022-22536 Exploit Probability: 93.8%
August 18, 2022
SAP NetWeaver Unrestricted File Upload vulnerability SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
CVE-2021-38163 Exploit Probability: 84.8%
June 9, 2022
SAP NetWeaver SQL Injection Vulnerability SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-2386 Exploit Probability: 44.0%
June 9, 2022
SAP NetWeaver Information Disclorsure Vulnerability The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
CVE-2016-2388 Exploit Probability: 62.3%
June 9, 2022
SAP NetWeaver AS JAVA CRM Remote Code Execution Vulnerability SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
CVE-2018-2380 Exploit Probability: 48.8%
November 3, 2021
SAP NetWeaver AS JAVA Remote Code Execution Vulnerability The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request.
CVE-2010-5326 Exploit Probability: 16.9%
November 3, 2021
SAP NetWeaver AS JAVA XXE Vulnerability BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
CVE-2016-9563 Exploit Probability: 58.4%
November 3, 2021
SAP Netweaver JAVA remote unauthenticated access vulnerability SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system.
CVE-2020-6287 Exploit Probability: 94.4%
November 3, 2021
SAP Solution Manager Missing Authentication Check Complete Compromise of SMD Agents vulnerability SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVE-2020-6207 Exploit Probability: 94.2%
November 3, 2021
SAP NetWeaver AS Java 7.1 - 7.5 Directory Traversal Vulnerability Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
CVE-2016-3976 Exploit Probability: 81.5%
November 3, 2021

Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited SAP vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 78 vulnerabilities in SAP with an average score of 6.1 out of ten. Last year, in 2025 SAP had 205 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in SAP in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.17




Year Vulnerabilities Average Score
2026 78 6.06
2025 205 6.23
2024 106 6.11
2023 167 6.71
2022 188 6.70
2021 204 6.74
2020 207 7.48
2019 124 6.67
2018 127 6.94

It may take a day or so for new SAP vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent SAP Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-34264 Apr 14, 2026
SAP S/4HANA HCM Auth Check Bypass reveals sensitive data During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
S4hana
CVE-2026-34262 Apr 14, 2026
SAP HANA Cockpit & DB Explorer Info Disclosure Vulnerability Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
Hana
CVE-2026-34261 Apr 14, 2026
SAP Business Analytics Auth Bypass via Remote Function Calls Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.
CVE-2026-34257 Apr 14, 2026
SAP NW AS ABAP Open Redirect Vulnerability Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
Netweaver Application Server Abap
CVE-2026-34256 Apr 14, 2026
SAP ERP/S4HANA ABAP Report Overwrite via Missing Auth Check Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended functionality could become unavailable. Successful exploitation impacts availability, with a limited impact on integrity confined to the affected report, while confidentiality remains unaffected.
S4hana
CVE-2026-27683 Apr 14, 2026
SAP BusinessObjects XSS via URL injection low confidentiality impact SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the users browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.
Businessobjects Business Intelligence Platform
CVE-2026-27681 Apr 14, 2026
SAP BPC & BW Bypass Auth: Authenticated User Can Execute SQL Injection Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
Business Warehouse
CVE-2026-27679 Apr 14, 2026
High-Integrity OData Auth Bypass in SAP S/4HANA Frontend Due to missing authorization checks in the SAP S/4HANA frontend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted.
S4hana
CVE-2026-27678 Apr 14, 2026
SAP S/4HANA OData Authz Bypass Update/Delete Child Entities without proper Auth Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted.
S4hana
CVE-2026-27677 Apr 14, 2026
Auth Bypass: SAP S/4HANA OData Delete/Update RefEquip Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted.
S4hana
CVE-2026-27676 Apr 14, 2026
SAP S/4HANA OData Service Auth Bypass: Delete/Update Child Entities Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability results in a low impact on integrity, while confidentiality and availability are not impacted.
S4hana
CVE-2026-27675 Apr 14, 2026
SAP Landscape Transformation RFC Function Module Code Injection Vulnerability SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a low impact on integrity, while confidentiality and availability are not impacted.
CVE-2026-27674 Apr 14, 2026
Code Injection in SAP NetWeaver AS Java Web Dynpro (CVE-2026-27674) Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in the victims browser, potentially resulting in session compromise. This could allow the attacker to execute arbitrary client-side code, impacting the confidentiality and integrity of the application, with no impact to availability.
Netweaver Application Server Java
CVE-2026-27673 Apr 14, 2026
SAP S/4HANA OS File Deletion via Missing Auth Check Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
S4hana
CVE-2026-27672 Apr 14, 2026
SAP Material Master RBAC Bypass via Report Execution The Material Master application does not enforce authorization checks for authenticated users when executing reports, resulting in the disclosure of sensitive information. This vulnerability has a low impact on confidentiality and does not affect integrity and availability of the system.
CVE-2026-24318 Apr 14, 2026
Insecure Session Management in SAP BO BI Platform Reuses Tokens Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victims session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victims authenticated context. This could allow the attacker to access or modify information within the victims session scope, impacting confidentiality and integrity, while availability remains unaffected.
Businessobjects Business Intelligence Platform
CVE-2026-0512 Apr 14, 2026
SAP SRM Catalog XSS via SICF Handler: Unauth CVE-2026-0512 Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL, that if accessed by a victim, results in execution of malicious content within the victim's browser. This could allow the attacker to access and modify information, impacting the confidentiality and integrity of the application, while availability remains unaffected.
CVE-2026-27689 Mar 10, 2026
SAP DOS via Large Loop in Remote Function Module Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
CVE-2026-27688 Mar 10, 2026
Missing Auth Check in SAP NetWeaver AS ABAP Allows Log Access Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data, resulting in a limited impact on the confidentiality of the information stored. However, the integrity and availability of the system are not affected.
Netweaver Application Server Abap
CVE-2026-27687 Mar 10, 2026
Missing Access Control in SAP S/4HANA HCM Enables Privileged Data Access Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.
S4hana
CVE-2026-27686 Mar 10, 2026
SAP BW Service API Missing Auth Check Enables Unauthorized RFC Changes Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Business Warehouse
CVE-2026-27685 Mar 10, 2026
Deserialization Remote Code Exec in SAP NetWeaver Enterprise Portal Admin SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
NetWeaver
CVE-2026-27684 Mar 10, 2026
SQLi in SAP NetWeaver Feedback Notifications Service SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an attacker can manipulate the WHERE clause logic and potentially gain unauthorized access to or modify database information. This vulnerability has no impact on integrity and low impact on the confidentiality and availability of the application.
NetWeaver
CVE-2026-24317 Mar 10, 2026
Arbitrary Dir DLL Load RCE in SAP GUI Windows SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.
CVE-2026-24316 Mar 10, 2026
SAP NetWeaver AS for ABAP SSRF via ABAP Report SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with potentially sensitive internal endpoints, resulting in a low impact on data confidentiality and integrity. There is no impact on availability of the application.
Netweaver Application Server Abap
CVE-2026-24313 Mar 10, 2026
SAP ST-PI: Auth-Check Bypass Allows System Info Disclosure SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.
CVE-2026-24311 Mar 10, 2026
SAP Customer Checkout: Local Data Modify Abuse via Insecure Reverse Protection The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could affect system behaviour during startup, resulting in a high impact on the application's confidentiality and integrity, with a low impact on availability.
CVE-2026-24310 Mar 10, 2026
SAP NetWeaver AS ABAP: Auth Bypass Allows Sensitive DB Read (CVE-2026-24310) Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on the integrity and availability.
Netweaver Application Server Abap
CVE-2026-24309 Mar 10, 2026
SAP NetWeaver AppSrv ABAP: Auth Bypass Allows DB Config Mod Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.
Netweaver Application Server Abap
CVE-2026-0489 Mar 10, 2026
SAP Business One Job Service DOM XSS via Unvalidated URL Query Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.
Business One
CVE-2026-24314 Feb 24, 2026
Authenticated Info Disclosure in SAP S/4HANA Payment Media Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
S4hana
CVE-2026-24328 Feb 10, 2026
SAP TAF_APPLAUNCHER Open Redirect via crafted link SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victims browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
CVE-2026-24327 Feb 10, 2026
SAP Strategic Enterprise Management - Unauthorized Access via Missing Auth Check Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.
CVE-2026-24326 Feb 10, 2026
SAP S/4HANA DefSec: Missing Auth in Disconnected Ops Enables FM Table Update Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.
S4hana
CVE-2026-24325 Feb 10, 2026
SAP BusinessObjects Enterprise Stored XSS via inadequate input encoding SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.
Businessobjects
CVE-2026-24324 Feb 10, 2026
SAP BusinessObjects BI Platform AdminTools Denial-of-Service via CMS Crash SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.
Businessobjects Business Intelligence Platform
CVE-2026-24323 Feb 10, 2026
XSS in BSP Web App via Unsanitized URL Params The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victims browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.
CVE-2026-24322 Feb 10, 2026
Authorization Bypass in SAP ST-PI Enables Sensitive Data Disclosure SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.
CVE-2026-24321 Feb 10, 2026
SAP Commerce Cloud Open API Endpoint Disclosure (Unauth) SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.
Commerce Cloud
CVE-2026-24320 Feb 10, 2026
SAP NetWeaver ABAP MemCorrupt Exploit CVE-2026-24320 Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.
NetWeaver
CVE-2026-24319 Feb 10, 2026
CVE-2026-24319: SAP Business One Memory Dump Info Disclosure In SAP Business One, sensitive information is written to the applications memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.
Business One
CVE-2026-24312 Feb 10, 2026
SAP Business Workflow Priv Escalation via Auth Check An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.
CVE-2026-23689 Feb 10, 2026
DoS via uncontrolled loop in SAP NetWeaver Remote-Enabled Function Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
CVE-2026-23688 Feb 10, 2026
SAP Fiori App Manage Service Entry Sheets PrivEsc via Missing Auth Checks SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.
CVE-2026-23687 Feb 10, 2026
SAP NetWeaver ABAP Signed XML Tampering Attack SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.
NetWeaver
CVE-2026-23686 Feb 10, 2026
CRLF Injection in SAP NetWeaver Application Server Java Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.
Netweaver Application Server Java
CVE-2026-23685 Feb 10, 2026
SAP NetWeaver JMS Deserialization: High Impact DoS Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.
NetWeaver
CVE-2026-23684 Feb 10, 2026
SAP Commerce Cloud Cart Entry Race Condition A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.
Commerce Cloud
CVE-2026-23681 Feb 10, 2026
SAP Support Tools Plug-In: Function-Module Authorization Bypass Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This vulnerability has a low impact on the confidentiality of the application, with no effect on its integrity or availability.
CVE-2026-0509 Feb 10, 2026
SAP NetWeaver App Server ABAP Remote Function Call Auth ByPass SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.
Netweaver Application Server Abap
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.