SAP

SAP NetWeaver

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 12.08.2025 02:05:34
  • Zuletzt bearbeitet 12.08.2025 14:25:33

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon...

  • EPSS 0.03%
  • Veröffentlicht 12.08.2025 02:05:19
  • Zuletzt bearbeitet 12.08.2025 14:25:33

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to pr...

  • EPSS 0.02%
  • Veröffentlicht 12.08.2025 02:05:09
  • Zuletzt bearbeitet 12.08.2025 14:25:33

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This lea...

  • EPSS 0.04%
  • Veröffentlicht 08.07.2025 00:38:32
  • Zuletzt bearbeitet 08.07.2025 16:18:14

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low i...

  • EPSS 0.09%
  • Veröffentlicht 08.07.2025 00:38:16
  • Zuletzt bearbeitet 08.07.2025 16:18:14

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script execut...

Medienbericht
  • EPSS 0.07%
  • Veröffentlicht 08.07.2025 00:38:07
  • Zuletzt bearbeitet 08.07.2025 16:18:14

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability o...

  • EPSS 0.02%
  • Veröffentlicht 08.07.2025 00:37:44
  • Zuletzt bearbeitet 08.07.2025 16:18:14

The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of rem...

  • EPSS 0.04%
  • Veröffentlicht 08.07.2025 00:37:33
  • Zuletzt bearbeitet 08.07.2025 16:18:14

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is ...

  • EPSS 0.13%
  • Veröffentlicht 08.07.2025 00:36:41
  • Zuletzt bearbeitet 08.07.2025 16:18:14

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payl...

  • EPSS 0.04%
  • Veröffentlicht 08.07.2025 00:36:31
  • Zuletzt bearbeitet 08.07.2025 16:18:14

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditi...