SAP

Security Scorecard

Score

71C

Total CVEs

44

Patch Rate

50%

22 patched

Avg Response

-

days to patch

Critical Gaps

1

exploitable, no detection

Severity Breakdown

Critical6
High6
Medium32
Low0

Patch Status

Patched22 (50%)
Partial/Workaround4 (9%)
Unpatched18 (41%)

CVEs (44)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-0500SAP WorkStation VulnerabilityCritical9.6-Workaround
CVE-2026-0501SAP S/4HANA Financials General Ledger SQL InjectionCritical9.9-Patched
CVE-2026-0503SAP ECC and S/4HANA EHS Management Auth BypassMedium6.4-Workaround
CVE-2026-0507SAP Application Server for ABAP OS Command InjectionHigh8.4-Patched
CVE-2026-0511SAP Fiori App Intercompany Balance Reconciliation VulnerabilityHigh8.1-Patched
CVE-2026-0513SAP SICF Handler Open Redirect VulnerabilityMedium4.7-Patched
CVE-2026-0514SAP Business Connector XSSMedium6.1-Patched
CVE-2025-42880CVE-2025-42880Critical9.9-Patched
CVE-2025-42878SAP Web Dispatcher and ICM Internal Testing Interface BypassHigh8.2-Workaround
CVE-2025-42874SAP NetWeaver Remote Service Xcelsius BypassHigh7.9-Patched