SAP Vulnerabilities
SAP makes enterprise applications for finance, procurement, HR and supply chain, and many of its on-premises products run on the SAP NetWeaver platform. The database tracks 14 SAP CVE records. CISA lists 14 of them as exploited in the wild, most recently on 2025-05-15. The most affected products are NetWeaver, Commerce Cloud, Customer Relationship Management (CRM).
Recently Exploited SAP CVEs
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
SAP NetWeaver Directory Traversal Vulnerability
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
SAP Multiple Products HTTP Request Smuggling Vulnerability
SAP NetWeaver SQL Injection Vulnerability
Affected Products
5 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| NetWeaver | 10 | 10 | 2025-05-15 |
| Commerce Cloud | 1 | 1 | 2024-09-30 |
| Customer Relationship Management (CRM) | 1 | 1 | 2021-11-03 |
| Multiple Products | 1 | 1 | 2022-08-18 |
| Solution Manager | 1 | 1 | 2021-11-03 |
All SAP CVEs
14 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-42999 | Insecure Deserialization in SAP NetWeaver (Visual Composer development server) | SAP_SE | 9.1 | 13.9% | KEV | 2025-05-13 |
| CVE-2025-31324 | Missing Authorization check in SAP NetWeaver (Visual Composer development server) | SAP_SE | 10.0 | 99.5% | KEV | 2025-04-24 |
| CVE-2017-12637 | SAP NetWeaver Directory Traversal Vulnerability | - | 7.5 | 95.1% | KEV | 2017-08-07 |
| CVE-2019-0344 | SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability | SAP SE | 9.8 | 7.1% | KEV | 2019-08-14 |
| CVE-2022-22536 | SAP Multiple Products HTTP Request Smuggling Vulnerability | SAP SE | 9.8 | 97.9% | KEV | 2022-02-09 |
| CVE-2016-2386 | SAP NetWeaver SQL Injection Vulnerability | - | 9.8 | 71.5% | KEV | 2016-02-16 |
| CVE-2016-2388 | SAP NetWeaver Information Disclosure Vulnerability | - | 5.3 | 52.2% | KEV | 2016-02-16 |
| CVE-2021-38163 | SAP NetWeaver Unrestricted File Upload Vulnerability | SAP SE | 9.9 | 36.9% | KEV | 2021-09-14 |
| CVE-2020-6207 | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | SAP SE | 10.0 | 98.1% | KEV | 2020-03-10 |
| CVE-2020-6287 | SAP NetWeaver Missing Authentication for Critical Function Vulnerability | SAP SE | 10.0 | 94.7% | KEV | 2020-07-14 |
| CVE-2016-3976 | SAP NetWeaver Directory Traversal Vulnerability | - | 7.5 | 47.3% | KEV | 2016-04-07 |
| CVE-2018-2380 | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | SAP SE | 6.6 | 28.9% | KEV | 2018-03-01 |
| CVE-2016-9563 | SAP NetWeaver XML External Entity (XXE) Vulnerability | - | 6.5 | 24.2% | KEV | 2016-11-23 |
| CVE-2010-5326 | SAP NetWeaver Remote Code Execution Vulnerability | - | 10.0 | 17.8% | KEV | 2016-05-13 |
Frequently Asked Questions
How many SAP vulnerabilities are actively exploited?→
14 SAP CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2025-05-15.
Which SAP vulnerabilities are used in ransomware attacks?→
CISA marks 3 SAP KEV entries as known to be used in ransomware campaigns, including CVE-2025-42999, CVE-2025-31324, CVE-2018-2380.
Which SAP products have the most exploited vulnerabilities?→
- +NetWeaver: 10 CVEs (10 in KEV)
- +Commerce Cloud: 1 CVE (1 in KEV)
- +Customer Relationship Management (CRM): 1 CVE (1 in KEV)
- +Multiple Products: 1 CVE (1 in KEV)
- +Solution Manager: 1 CVE (1 in KEV)
Where does SAP publish security advisories?→
SAP publishes security advisories at https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by SAP, MITRE, CISA, or FIRST.