SAP_SE 厂商相关 555 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
SAP SE 是全球领先的企业应用软件供应商,其核心产品涵盖 ERP、CRM 及数据分析平台。历史漏洞多集中于远程代码执行、身份验证绕过及跨站脚本,常因复杂集成逻辑或配置缺陷引发。近期关注点包括云环境下的权限管理风险及供应链依赖问题。作为关键基础设施提供商,其系统稳定性与数据完整性对众多大型企业至关重要,需持续强化补丁管理与访问控制机制。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-44757 | SAP Wily Introscope Enterprise Manager 跨站脚本漏洞 — SAP Wily Introscope Enterprise ManagerCWE-79 | 4.7 | Medium | 2026-06-09 |
| CVE-2026-44755 | SAP BusinessObjects BI平台邮件伪造漏洞 — SAP Business Objects Business Intelligence PlatformCWE-346 | 4.3 | Medium | 2026-06-09 |
| CVE-2026-44754 | ODP数据复制API缺少调用者身份验证 — ODP Data Replication APIsCWE-862 | 6.6 | Medium | 2026-06-09 |
| CVE-2026-44751 | SAP NetWeaver ABAP应用服务器缺失授权检查漏洞 — SAP NetWeaver AS ABAP and ABAP PlatformCWE-862 | 7.1 | High | 2026-06-09 |
| CVE-2026-44750 | SAP MDG 缺少身份验证检查漏洞 — SAP MDG (Review Match Groups Application)CWE-862 | 4.3 | Medium | 2026-06-09 |
| CVE-2026-44748 | SAP NetWeaver AS ABAP SAML认证XML签名包装漏洞 — SAP NetWeaver AS ABAP and ABAP PlatformCWE-347 | 9.9 | Critical | 2026-06-09 |
| CVE-2026-44746 | SAP NetWeaver AS Java JDBC测试服务反射型XSS漏洞 — SAP NetWeaver AS Java (JDBC Test Servlet)CWE-79 | 6.1 | Medium | 2026-06-09 |
| CVE-2026-44744 | SAP S/4HANA 存在SQL注入漏洞 — SAP S/4HANACWE-89 | 6.5 | Medium | 2026-06-09 |
| CVE-2026-44743 | SAP Business Objects 安全配置错误漏洞 — SAP Business ObjectsCWE-497 | 3.7 | Low | 2026-06-09 |
| CVE-2026-40128 | SAP NetWeaver Java 服务器目录遍历漏洞 — SAP NetWeaver Application Server Java (Web Container)CWE-35 | 9.0 | Critical | 2026-06-09 |
| CVE-2026-27671 | SAP NetWeaver及ABAP平台应用服务器ABAP内存损坏漏洞 — SAP NetWeaver AS ABAP and ABAP PlatformCWE-121 | 9.8 | Critical | 2026-06-09 |
| CVE-2026-24315 | SAP Fiori 路径遍历漏洞 — SAP Fiori (launchpad)CWE-35 | 4.2 | Medium | 2026-06-09 |
| CVE-2026-44749 | SAP Gateway 安全漏洞 — SAP GatewayCWE-497 | 4.3 | Medium | 2026-05-26 |
| CVE-2026-27680 | SAP NetWeaver Application Server ABAP 安全漏洞 — SAP NetWeaver Application Server ABAPCWE-276 | 3.1 | Low | 2026-05-14 |
| CVE-2026-40137 | SAP Business Server Pages Application 跨站脚本漏洞 — Business Server Pages Application (TAF_APPLAUNCHER)CWE-79 | 6.1 | Medium | 2026-05-12 |
| CVE-2026-40136 | SAP Financial Consolidation 安全漏洞 — SAP Financial ConsolidationCWE-404 | 4.3 | Medium | 2026-05-12 |
| CVE-2026-40135 | SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP 命令注入漏洞 — SAP NetWeaver Application Server for ABAP and ABAP PlatformCWE-77 | 6.5 | Medium | 2026-05-12 |
| CVE-2026-40134 | SAP Incentive and Commission Management 安全漏洞 — SAP Incentive and Commission ManagementCWE-862 | 4.3 | Medium | 2026-05-12 |
| CVE-2026-40133 | SAP S/4HANA Condition Maintenance 安全漏洞 — SAP S/4HANA Condition MaintenanceCWE-862 | 6.3 | Medium | 2026-05-12 |
| CVE-2026-40132 | SAP Strategic Enterprise Management 安全漏洞 — SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)CWE-862 | 5.4 | Medium | 2026-05-12 |
| CVE-2026-40131 | SAP HANA Deployment Infrastructure deploy library SQL注入漏洞 — SAP HANA Deployment Infrastructure (HDI) deploy libraryCWE-89 | 3.4 | Low | 2026-05-12 |
| CVE-2026-40129 | SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP 代码注入漏洞 — SAP Application Server ABAP for SAP NetWeaver and ABAP PlatformCWE-94 | 4.3 | Medium | 2026-05-12 |
| CVE-2026-34263 | SAP Commerce Cloud 安全漏洞 — SAP Commerce cloud configurationCWE-459 | 9.6 | Critical | 2026-05-12 |
| CVE-2026-34260 | SAP S/4HANA SQL注入漏洞 — SAP S/4HANA (SAP Enterprise Search for ABAP)CWE-89 | 9.6 | Critical | 2026-05-12 |
| CVE-2026-34259 | SAP Forecasting and Replenishment 命令注入漏洞 — SAP Forecasting & ReplenishmentCWE-77 | 8.2 | High | 2026-05-12 |
| CVE-2026-34258 | SAP SAPUI5 安全漏洞 — SAPUI5 (Search UI)CWE-451 | 4.7 | Medium | 2026-05-12 |
| CVE-2026-27682 | SAP NetWeaver Application Server ABAP 跨站脚本漏洞 — SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)CWE-79 | 4.7 | Medium | 2026-05-12 |
| CVE-2026-0502 | SAP BusinessObjects Business Intelligence Platform 跨站请求伪造漏洞 — SAP BusinessObjects Business Intelligence PlatformCWE-352 | 5.4 | Medium | 2026-05-12 |
| CVE-2026-34264 | SAP Human Capital Management 安全漏洞 — SAP Human Capital Management for SAP S/4HANACWE-204 | 6.5 | Medium | 2026-04-14 |
| CVE-2026-34262 | SAP HANA Cockpit和SAP HANA Database Explorer 安全漏洞 — SAP HANA Cockpit and HANA Database ExplorerCWE-522 | 5.0 | Medium | 2026-04-14 |
本页汇总了 SAP_SE 厂商截至目前公开的全部 555 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。