CVE-2026-34257
- EPSS 0.16%
- Veröffentlicht 14.04.2026 00:08:39
- Zuletzt bearbeitet 03.06.2026 19:06:45
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impa...
CVE-2026-27674
- EPSS 0.19%
- Veröffentlicht 14.04.2026 00:06:50
- Zuletzt bearbeitet 03.06.2026 19:05:51
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If...
- EPSS 0.23%
- Veröffentlicht 10.03.2026 00:18:55
- Zuletzt bearbeitet 03.06.2026 18:58:26
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to...
CVE-2026-27685
- EPSS 0.55%
- Veröffentlicht 10.03.2026 00:18:22
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
CVE-2026-27684
- EPSS 0.27%
- Veröffentlicht 10.03.2026 00:18:10
- Zuletzt bearbeitet 11.03.2026 13:53:47
SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL q...
CVE-2026-24316
- EPSS 0.16%
- Veröffentlicht 10.03.2026 00:17:51
- Zuletzt bearbeitet 03.06.2026 18:55:32
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successf...
CVE-2026-24310
- EPSS 0.19%
- Veröffentlicht 10.03.2026 00:17:21
- Zuletzt bearbeitet 03.06.2026 18:59:33
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has...
CVE-2026-24309
- EPSS 0.21%
- Veröffentlicht 10.03.2026 00:17:12
- Zuletzt bearbeitet 03.06.2026 18:54:02
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This un...
CVE-2026-24320
- EPSS 0.24%
- Veröffentlicht 10.02.2026 03:03:42
- Zuletzt bearbeitet 17.02.2026 15:27:30
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are i...
CVE-2026-23687
- EPSS 0.46%
- Veröffentlicht 10.02.2026 03:02:47
- Zuletzt bearbeitet 09.06.2026 08:16:27
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identit...