SAP

SAP NetWeaver

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.04%
  • Veröffentlicht 09.09.2025 02:15:42
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to ...

  • EPSS 0.08%
  • Veröffentlicht 09.09.2025 02:15:41
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is pro...

  • EPSS 0.01%
  • Veröffentlicht 09.09.2025 02:15:41
  • Zuletzt bearbeitet 09.09.2025 16:28:43

SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and ...

  • EPSS 0.09%
  • Veröffentlicht 09.09.2025 02:15:41
  • Zuletzt bearbeitet 09.09.2025 16:28:43

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gathe...

  • EPSS 0.03%
  • Veröffentlicht 09.09.2025 02:15:40
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of severa...

Medienbericht
  • EPSS 0.05%
  • Veröffentlicht 09.09.2025 02:15:40
  • Zuletzt bearbeitet 09.09.2025 16:28:43

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availabilit...

  • EPSS 0.03%
  • Veröffentlicht 09.09.2025 02:15:40
  • Zuletzt bearbeitet 09.09.2025 16:28:43

SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availab...

  • EPSS 0.03%
  • Veröffentlicht 09.09.2025 02:15:38
  • Zuletzt bearbeitet 09.09.2025 16:28:43

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no eff...

  • EPSS 0.12%
  • Veröffentlicht 12.08.2025 02:08:17
  • Zuletzt bearbeitet 12.08.2025 14:25:33

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is process...

  • EPSS 0.03%
  • Veröffentlicht 12.08.2025 02:05:51
  • Zuletzt bearbeitet 12.08.2025 14:25:33

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerabi...