CVE-2024-39599
- EPSS 0.03%
- Published 09.07.2024 05:15:12
- Last modified 21.11.2024 09:28:05
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidenti...
CVE-2024-37180
- EPSS 0.04%
- Published 09.07.2024 05:15:12
- Last modified 21.11.2024 09:23:22
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-s...
CVE-2024-32733
- EPSS 0.12%
- Published 14.05.2024 16:17:10
- Last modified 21.11.2024 09:15:35
Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successfu...
CVE-2024-30218
- EPSS 0.17%
- Published 09.04.2024 01:15:50
- Last modified 21.11.2024 09:11:28
The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable impact on availability.
CVE-2024-27899
- EPSS 0.12%
- Published 09.04.2024 01:15:48
- Last modified 21.11.2024 09:05:22
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound im...