Loading HuntDB...

sap_se

191 Products 253 CVEs

CVE Severity Distribution (All Time)

Critical
17
High
50
Medium
165
Low
21

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 14 CVEs
Last Year 93 CVEs

Recent CVEs

View all
CVE-2025-0070 CRITICAL 5 months, 1 week ago

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploitin…

CVE-2025-0069 HIGH 5 months, 1 week ago

Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Window…

CVE-2025-0068 MEDIUM 5 months, 1 week ago

An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated …

CVE-2025-0067 MEDIUM 5 months, 1 week ago

Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can creat…

CVE-2025-0066 CRITICAL 5 months, 1 week ago

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor…

CVE-2025-0063 HIGH 5 months, 1 week ago

SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attack…

CVE-2025-0061 HIGH 5 months, 1 week ago

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user …

CVE-2025-0060 MEDIUM 5 months, 1 week ago

SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sen…

CVE-2025-0059 MEDIUM 5 months, 1 week ago

Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. A…

CVE-2025-0058 MEDIUM 5 months, 1 week ago

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request …

Related Security News

Critical SAP Flaws Revealed: CVE-2025-0070 and CVE-2025-0066 with CVSS 9.9 Demand Immediate Action
2025-01-14 07:23 SecurityOnline.info

Today, SAP released 14 new security notes during its monthly Security Patch Day. This release includes several critical The post Critical SAP Flaws Revealed: CVE-2025-0070 and CVE-2025-0066 with CVSS…