SAP

SAP NetWeaver

102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 10.03.2026 00:17:12
  • Zuletzt bearbeitet 11.03.2026 13:53:47

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This un...

  • EPSS 0.01%
  • Veröffentlicht 10.02.2026 03:03:42
  • Zuletzt bearbeitet 17.02.2026 15:27:30

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are i...

  • EPSS 0.02%
  • Veröffentlicht 10.02.2026 03:02:47
  • Zuletzt bearbeitet 17.02.2026 16:12:35

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identit...

  • EPSS 0.04%
  • Veröffentlicht 10.02.2026 03:02:37
  • Zuletzt bearbeitet 17.02.2026 16:03:09

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables inje...

  • EPSS 0.21%
  • Veröffentlicht 10.02.2026 03:02:27
  • Zuletzt bearbeitet 17.02.2026 16:04:13

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger u...

Medienbericht
  • EPSS 0.02%
  • Veröffentlicht 10.02.2026 03:01:52
  • Zuletzt bearbeitet 17.02.2026 16:04:59

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity ...

  • EPSS 0.01%
  • Veröffentlicht 10.02.2026 03:00:41
  • Zuletzt bearbeitet 17.02.2026 16:12:08

Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity ...

Medienbericht
  • EPSS 1.38%
  • Veröffentlicht 13.01.2026 01:15:36
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If proces...

Medienbericht
  • EPSS 0.07%
  • Veröffentlicht 13.01.2026 01:14:33
  • Zuletzt bearbeitet 22.01.2026 18:48:00

Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attac...

  • EPSS 0.21%
  • Veröffentlicht 13.01.2026 01:13:47
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft o...