SAP

Security Scorecard

Score

71C

Total CVEs

44

Patch Rate

50%

22 patched

Avg Response

-

days to patch

Critical Gaps

1

exploitable, no detection

Severity Breakdown

Critical6
High6
Medium32
Low0

Patch Status

Patched22 (50%)
Partial/Workaround4 (9%)
Unpatched18 (41%)

CVEs (44)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-42876SAP S/4 HANA Private Cloud Financials General Ledger VulnerabilityHigh7.1-Patched
CVE-2025-42875SAP Internet Communication Framework VulnerabilityMedium6.6-Patched
CVE-2025-42904ABAP List Information DisclosureMedium6.5-Workaround
CVE-2025-42872SAP NetWeaver Enterprise Portal XSS VulnerabilityMedium6.1-Patched
CVE-2025-42873SAPUI5 Infinite Loop Denial of ServiceMedium5.9-Patched
CVE-2025-42891SAP Enterprise Search for ABAP VulnerabilityMedium5.5-Patched
CVE-2025-42924-Medium6.134dUnpatched
CVE-2025-42919-Medium5.334dUnpatched
CVE-2025-42897-Medium5.335dUnpatched
CVE-2025-42895-Medium6.935dUnpatched