SAP

SAP NetWeaver

75 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warning Media report
  • EPSS 30.15%
  • Published 24.04.2025 16:50:27
  • Last modified 06.05.2025 20:59:33

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...

  • EPSS 0.04%
  • Published 08.04.2025 07:14:37
  • Last modified 08.04.2025 18:13:53

Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the out...

  • EPSS 0.03%
  • Published 08.04.2025 07:13:58
  • Last modified 08.04.2025 18:13:53

A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access bu...

  • EPSS 0.13%
  • Published 08.04.2025 07:13:27
  • Last modified 08.04.2025 18:13:53

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solutio...

  • EPSS 0.02%
  • Published 08.04.2025 07:10:34
  • Last modified 08.04.2025 18:13:53

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a w...

  • EPSS 0.04%
  • Published 08.04.2025 07:10:22
  • Last modified 08.04.2025 18:13:53

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials ca...

  • EPSS 0.03%
  • Published 11.03.2025 01:15:36
  • Last modified 11.03.2025 01:15:36

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality,...

  • EPSS 0.04%
  • Published 11.03.2025 01:15:35
  • Last modified 11.03.2025 01:15:35

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI...

  • EPSS 0.04%
  • Published 11.03.2025 01:15:34
  • Last modified 11.03.2025 01:15:34

SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor...

  • EPSS 0.09%
  • Published 11.03.2025 01:15:34
  • Last modified 11.03.2025 01:15:34

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confi...