SAP

SAP NetWeaver

82 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 08.04.2025 07:13:27
  • Zuletzt bearbeitet 08.04.2025 18:13:53

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solutio...

  • EPSS 0.03%
  • Veröffentlicht 08.04.2025 07:10:34
  • Zuletzt bearbeitet 08.04.2025 18:13:53

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a w...

  • EPSS 0.05%
  • Veröffentlicht 08.04.2025 07:10:22
  • Zuletzt bearbeitet 08.04.2025 18:13:53

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials ca...

  • EPSS 0.05%
  • Veröffentlicht 11.03.2025 01:15:36
  • Zuletzt bearbeitet 11.03.2025 01:15:36

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality,...

  • EPSS 0.06%
  • Veröffentlicht 11.03.2025 01:15:35
  • Zuletzt bearbeitet 11.03.2025 01:15:35

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI...

  • EPSS 0.06%
  • Veröffentlicht 11.03.2025 01:15:34
  • Zuletzt bearbeitet 11.03.2025 01:15:34

SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor...

  • EPSS 0.09%
  • Veröffentlicht 11.03.2025 01:15:34
  • Zuletzt bearbeitet 11.03.2025 01:15:34

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confi...

  • EPSS 0.08%
  • Veröffentlicht 11.02.2025 01:15:11
  • Zuletzt bearbeitet 18.02.2025 18:15:33

SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, ...

  • EPSS 0.08%
  • Veröffentlicht 11.02.2025 01:15:10
  • Zuletzt bearbeitet 11.02.2025 01:15:10

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability

  • EPSS 0.22%
  • Veröffentlicht 11.02.2025 01:15:10
  • Zuletzt bearbeitet 18.02.2025 18:15:33

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.