- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:18:55
- Zuletzt bearbeitet 11.03.2026 13:53:47
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to...
CVE-2026-27685
- EPSS 0.06%
- Veröffentlicht 10.03.2026 00:18:22
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
CVE-2026-27684
- EPSS 0.04%
- Veröffentlicht 10.03.2026 00:18:10
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL q...
CVE-2026-24316
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:51
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successf...
CVE-2026-24310
- EPSS 0.03%
- Veröffentlicht 10.03.2026 00:17:21
- Zuletzt bearbeitet 11.03.2026 13:53:47
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has...
CVE-2026-24309
- EPSS 0.04%
- Veröffentlicht 10.03.2026 00:17:12
- Zuletzt bearbeitet 11.03.2026 13:53:47
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This un...
CVE-2026-24320
- EPSS 0.01%
- Veröffentlicht 10.02.2026 03:03:42
- Zuletzt bearbeitet 17.02.2026 15:27:30
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are i...
CVE-2026-23687
- EPSS 0.02%
- Veröffentlicht 10.02.2026 03:02:47
- Zuletzt bearbeitet 17.02.2026 16:12:35
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identit...
CVE-2026-23686
- EPSS 0.03%
- Veröffentlicht 10.02.2026 03:02:37
- Zuletzt bearbeitet 17.02.2026 16:03:09
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables inje...
CVE-2026-23685
- EPSS 0.11%
- Veröffentlicht 10.02.2026 03:02:27
- Zuletzt bearbeitet 17.02.2026 16:04:13
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger u...