CVE-2025-0058
- EPSS 0.09%
- Veröffentlicht 14.01.2025 01:15:16
- Zuletzt bearbeitet 24.10.2025 19:22:46
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the abi...
CVE-2025-0053
- EPSS 0.13%
- Veröffentlicht 14.01.2025 01:15:15
- Zuletzt bearbeitet 24.10.2025 19:24:55
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This...
CVE-2024-39599
- EPSS 0.03%
- Veröffentlicht 09.07.2024 05:15:12
- Zuletzt bearbeitet 28.10.2025 18:40:44
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidenti...
CVE-2024-37180
- EPSS 0.11%
- Veröffentlicht 09.07.2024 05:15:12
- Zuletzt bearbeitet 29.10.2025 14:44:33
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-s...
- EPSS 0.28%
- Veröffentlicht 09.07.2024 05:15:10
- Zuletzt bearbeitet 21.11.2024 09:19:12
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It ha...
- EPSS 0.13%
- Veröffentlicht 14.05.2024 16:17:26
- Zuletzt bearbeitet 23.10.2025 20:28:16
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could r...
CVE-2016-4551
- EPSS 0.29%
- Veröffentlicht 05.10.2016 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.