VendorsSAPerpall versions
Vulnerabilities

SAP ERP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-6188
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.
Published 2020-02-12 · Modified
8.8EPSS 0.007
CVE-2014-2748
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from third party information.
Published 2014-04-10 · Modified
7.5EPSS 0.015
CVE-2026-0505
Multiple vulnerabilities in BSP Applications of SAP Document Management System
Published 2026-02-10 · Analyzed
6.1EPSS 0.002
CVE-2026-24323
Multiple vulnerabilities in BSP Applications of SAP Document Management System
Published 2026-02-10 · Analyzed
6.1EPSS 0.002
CVE-2020-6212
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.
Published 2020-04-24 · Modified
5.5EPSS 0.007
CVE-2020-6199
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.
Published 2020-03-10 · Modified
5.5EPSS 0.003
CVE-2020-6316
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.
Published 2020-11-10 · Modified
4.3EPSS 0.008