FAIL › dossier
SAP
VENDOR· dossier confidence 40%
SAP is a dominant enterprise software vendor whose core NetWeaver and CRM platforms are plagued by a persistent stream of critical vulnerabilities, including unauthenticated RCEs and memory corruption flaws. The company's security posture is characterized by a reactive patch cycle that struggles to keep pace with the severity and frequency of exploits targeting its foundational technologies.
PROFILE
CategoryEnterprise SoftwareWhat they doSAP is a German multinational software corporation that provides enterprise resource planning (ERP) and business management software.SizeLarge
Websitehttps://www.sap.com ↗
SECURITY POSTURE
SAP maintains a regular patch cycle but suffers from a high frequency of critical and high-severity vulnerabilities across its core NetWeaver and CRM platforms, often involving unauthenticated remote code execution, deserialization, and memory corruption flaws that require urgent patching.
Notable failures
- CVE-2025-31324: Unauthenticated RCE via Visual Composer Metadata Uploader
- CVE-2026-44747: Critical memory corruption in NetWeaver AS ABAP (CVSS 9.9)
- CVE-2025-42999: Privileged deserialization RCE in Visual Composer
- CVE-2018-2380: Path traversal in SAP CRM
- CVE-2019-0344: Deserialization of untrusted data in SAP Commerce Cloud
- CVE-2016-2386: SQL injection in UDDI server
Patterns: Repeated unauthenticated remote code execution (RCE) vulnerabilities in core NetWeaver components; Frequent deserialization of untrusted data leading to privilege escalation or RCE; Memory corruption and path traversal flaws in long-standing product lines
FAILURE HISTORY · 15
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-04-29 | CVE-2025-31324 | critical | An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment. |
| 2021-11-03 | CVE-2010-5326 | high | SAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests. |
| 2021-11-03 | CVE-2020-6287 | high | SAP NetWeaver allowed unauthenticated attackers to execute critical configuration tasks and create administrative users. |
| 2021-11-03 | CVE-2020-6207 | high | SAP Solution Manager's missing authentication for critical functions allowed complete compromise of all connected SMDAgents. |
| 2021-11-03 | CVE-2016-9563 | high | SAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code. |
| 2025-05-15 | CVE-2025-42999 | high | SAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability. |
| 2022-08-18 | CVE-2022-22536 | high | SAP's NetWeaver products exploited for HTTP request smuggling |
| 2022-06-09 | CVE-2016-2388 | high | SAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old. |
| 2022-06-09 | CVE-2021-38163 | high | SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration. |
| 2021-11-03 | CVE-2018-2380 | critical | A path traversal vulnerability in SAP CRM allowed attackers to access sensitive files without authorization, and it's currently being exploited in the wild. |
| 2021-11-03 | CVE-2016-3976 | high | SAP NetWeaver's CrashFileDownloadServlet allowed remote attackers to read arbitrary files via directory traversal. |
| 2024-09-30 | CVE-2019-0344 | high | SAP Commerce Cloud exploited via deserialization of untrusted data allows remote code injection. |
| 2022-06-09 | CVE-2016-2386 | high | A SQL injection vulnerability in SAP NetWeaver allowed attackers to execute arbitrary SQL commands remotely. |
| 2025-03-19 | CVE-2017-12637 | high | SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation. |
| 2025-04-24 | CVE-2025-31324 | critical | CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
SAP faced severe fallout for CVE-2016-9563, a critical XXE vulnerability in NetWeaver allowing remote authenticated attackers to exploit the flaw. The NVD entry confirms the severity, while other sour
synthesissevere-fallout-0.60
SAP faced significant scrutiny for a path traversal vulnerability in its CRM product, which could allow attackers to access unauthorized files or directories. The NVD entry highlights the severity of
synthesissevere-fallout-0.60
SAP faced severe criticism for a critical remote code execution vulnerability in NetWeaver that lacked authentication, exposing systems to unauthenticated remote code execution via HTTP/HTTPS requests
synthesisneutral+0.00
No sentiment expressed; sources are CVE databases or unrelated vendor advisories.
synthesissevere-fallout-0.60
SAP's vulnerability in Solution Manager allowed full compromise of connected agents due to missing authentication, representing a severe security failure.
synthesissevere-fallout-0.60
SAP faced severe criticism for a critical missing authentication flaw allowing unauthenticated administrative access, though the NVD entry itself is neutral and factual.
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Cisco vulnerabilities.
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Dell vulnerabilities.
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Zimbra vulnerabilities.
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 vulnerabilities.
SAP faced significant scrutiny for a path traversal vulnerability in its CRM product, which could allow attackers to access unauthorized files or directories. The NVD entry highlights the severity of
"SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users."
Neutral; NVD describes the vulnerability without sentiment.
"SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files."
Neutral; unrelated breach tracker page.
Neutral; vulnerability reference site.
Neutral; CVE database site.
Neutral; NVD page unrelated to CVE-2016-3976.
Neutral; Dell security advisory unrelated to SAP.
Neutral; Cisco security advisory unrelated to SAP.
neutral
"SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users."
NVD describes the vulnerability as resulting in complete compromise of all connected SMDAgents, indicating severe fallout.
"SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager."
SAP was heavily criticized for the unauthenticated Invoker Servlet vulnerability allowing remote code execution, highlighting a severe security oversight in NetWeaver.
"SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request."
NVD confirms critical XXE vulnerability in SAP NetWeaver, allowing remote authenticated attackers to exploit the flaw. No praise for SAP's handling is present in the provided text.
"SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks."
Irrelevant to SAP CVE-2016-9563; discusses unrelated 2026 Cisco vulnerabilities.
DOSSIER SOURCES
- SAP - Wikipedia · en.wikipedia.org
- Hasso Plattner & family - Forbes · www.forbes.com
- SAP Security Update July 2026 - Patch for Critical SAP NetWeaver Flaw ... · cybersecuritynews.com
- SAP Patch Day July 2026: Critical Vulnerabilities Demand Immediate ... · pathlock.com
- SAP Patch Day: CVE-2026-44747 Memory Corruption 9.9 · securityonline.info
Open questions: SAP's current patch response time for critical vulnerabilities · SAP's specific CMMC compliance status or self-assessment results
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:23:54.359681+00:00