Vendor
SAP vulnerabilities under active attack
14 SAP vulnerabilities have confirmed evidence of exploitation in the wild, and 2 are used in ransomware campaigns.
14
confirmed exploited
2
used in ransomware
14
past fix deadline
- CVE-2025-42999 SAP NetWeaver Deserialization Vulnerability SAP · NetWeaver
- CVE-2025-31324 SAP NetWeaver Unrestricted File Upload Vulnerability SAP · NetWeaver
- CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability SAP · NetWeaver
- CVE-2019-0344 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability SAP · Commerce Cloud
- CVE-2022-22536 SAP Multiple Products HTTP Request Smuggling Vulnerability SAP · Multiple Products
- CVE-2021-38163 SAP NetWeaver Unrestricted File Upload Vulnerability SAP · NetWeaver
- CVE-2016-2386 SAP NetWeaver SQL Injection Vulnerability SAP · NetWeaver
- CVE-2016-2388 SAP NetWeaver Information Disclosure Vulnerability SAP · NetWeaver
- CVE-2018-2380 SAP Customer Relationship Management (CRM) Path Traversal Vulnerability SAP · Customer Relationship Management (CRM)
- CVE-2010-5326 SAP NetWeaver Remote Code Execution Vulnerability SAP · NetWeaver
- CVE-2016-9563 SAP NetWeaver XML External Entity (XXE) Vulnerability SAP · NetWeaver
- CVE-2020-6287 SAP NetWeaver Missing Authentication for Critical Function Vulnerability SAP · NetWeaver
- CVE-2020-6207 SAP Solution Manager Missing Authentication for Critical Function Vulnerability SAP · Solution Manager
- CVE-2016-3976 SAP NetWeaver Directory Traversal Vulnerability SAP · NetWeaver