CVE-2026-27680
- EPSS 0.03%
- Veröffentlicht 14.05.2026 18:33:26
- Zuletzt bearbeitet 15.05.2026 14:11:57
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affecte...
CVE-2026-40135
- EPSS 0.17%
- Veröffentlicht 12.05.2026 02:21:40
- Zuletzt bearbeitet 12.05.2026 14:19:41
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the ...
CVE-2026-27682
- EPSS 0.02%
- Veröffentlicht 12.05.2026 02:19:26
- Zuletzt bearbeitet 12.05.2026 14:19:41
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a ma...
CVE-2026-34257
- EPSS 0.06%
- Veröffentlicht 14.04.2026 00:08:39
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impa...
CVE-2026-27674
- EPSS 0.08%
- Veröffentlicht 14.04.2026 00:06:50
- Zuletzt bearbeitet 17.04.2026 15:18:16
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If...
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:18:55
- Zuletzt bearbeitet 11.03.2026 13:53:47
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to...
CVE-2026-27685
- EPSS 0.06%
- Veröffentlicht 10.03.2026 00:18:22
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
CVE-2026-27684
- EPSS 0.04%
- Veröffentlicht 10.03.2026 00:18:10
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL q...
CVE-2026-24316
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:51
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successf...
CVE-2026-24310
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:21
- Zuletzt bearbeitet 11.03.2026 13:53:47
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has...