CVE-2026-44752
- EPSS 0.26%
- Veröffentlicht 14.07.2026 00:19:45
- Zuletzt bearbeitet 14.07.2026 16:46:49
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive sess...
CVE-2026-44747
- EPSS 0.53%
- Veröffentlicht 14.07.2026 00:19:33
- Zuletzt bearbeitet 29.07.2026 06:16:59
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high imp...
CVE-2026-44751
- EPSS 0.21%
- Veröffentlicht 09.06.2026 00:21:17
- Zuletzt bearbeitet 23.07.2026 08:10:00
Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker to execute a report generation command which could overwrite information belonging to another user, resulting in escalation of priv...
CVE-2026-44748
- EPSS 0.23%
- Veröffentlicht 09.06.2026 00:20:58
- Zuletzt bearbeitet 23.07.2026 08:10:00
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identit...
CVE-2026-44746
- EPSS 0.2%
- Veröffentlicht 09.06.2026 00:20:48
- Zuletzt bearbeitet 23.07.2026 08:10:00
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during ...
- EPSS 0.45%
- Veröffentlicht 09.06.2026 00:20:14
- Zuletzt bearbeitet 23.07.2026 08:10:00
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the i...
CVE-2026-27671
- EPSS 0.44%
- Veröffentlicht 09.06.2026 00:20:04
- Zuletzt bearbeitet 23.07.2026 08:10:00
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to...
CVE-2026-27680
- EPSS 0.17%
- Veröffentlicht 14.05.2026 18:33:26
- Zuletzt bearbeitet 03.06.2026 19:27:45
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affecte...
CVE-2026-40135
- EPSS 1.4%
- Veröffentlicht 12.05.2026 02:21:40
- Zuletzt bearbeitet 03.06.2026 18:33:28
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the ...
CVE-2026-27682
- EPSS 0.22%
- Veröffentlicht 12.05.2026 02:19:26
- Zuletzt bearbeitet 03.06.2026 19:08:54
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a ma...