SAP

SAP NetWeaver

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.88%
  • Veröffentlicht 13.01.2026 01:15:36
  • Zuletzt bearbeitet 13.01.2026 14:03:18

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If proces...

Medienbericht
  • EPSS 0.04%
  • Veröffentlicht 13.01.2026 01:14:33
  • Zuletzt bearbeitet 22.01.2026 18:48:00

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attac...

  • EPSS 0.08%
  • Veröffentlicht 13.01.2026 01:13:47
  • Zuletzt bearbeitet 13.01.2026 14:03:18

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft o...

Medienbericht
  • EPSS 0.08%
  • Veröffentlicht 09.12.2025 02:14:19
  • Zuletzt bearbeitet 09.12.2025 18:36:53

SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does...

Medienbericht
  • EPSS 0.09%
  • Veröffentlicht 09.12.2025 02:13:55
  • Zuletzt bearbeitet 09.12.2025 18:36:53

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tok...

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 11.11.2025 00:20:18
  • Zuletzt bearbeitet 12.11.2025 16:19:59

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path componen...

Medienbericht
  • EPSS 0.14%
  • Veröffentlicht 11.11.2025 00:14:02
  • Zuletzt bearbeitet 12.11.2025 16:19:59

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modifi...

Medienbericht
  • EPSS 0.04%
  • Veröffentlicht 11.11.2025 00:13:33
  • Zuletzt bearbeitet 12.11.2025 16:19:59

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This dis...

  • EPSS 0.02%
  • Veröffentlicht 14.10.2025 00:18:04
  • Zuletzt bearbeitet 14.10.2025 19:36:29

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated a...

  • EPSS 0.06%
  • Veröffentlicht 14.10.2025 00:17:32
  • Zuletzt bearbeitet 14.10.2025 19:36:29

Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which ...