CVE-2025-42989
- EPSS 0.43%
- Veröffentlicht 10.06.2025 00:12:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the applicatio...
CVE-2025-31325
- EPSS 0.27%
- Veröffentlicht 10.06.2025 00:10:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the s...
CVE-2025-42999
- EPSS 12.45%
- Veröffentlicht 13.05.2025 00:17:43
- Zuletzt bearbeitet 11.08.2026 04:17:17
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31329
- EPSS 0.34%
- Veröffentlicht 13.05.2025 00:16:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...
CVE-2025-31324
- EPSS 99.51%
- Veröffentlicht 24.04.2025 16:50:27
- Zuletzt bearbeitet 04.08.2026 05:16:34
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...
CVE-2025-30015
- EPSS 0.25%
- Veröffentlicht 08.04.2025 07:14:37
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the out...
CVE-2025-27437
- EPSS 0.26%
- Veröffentlicht 08.04.2025 07:13:58
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access bu...
CVE-2025-27428
- EPSS 0.59%
- Veröffentlicht 08.04.2025 07:13:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solutio...
CVE-2025-26653
- EPSS 0.23%
- Veröffentlicht 08.04.2025 07:10:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a w...
CVE-2025-23186
- EPSS 0.49%
- Veröffentlicht 08.04.2025 07:10:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials ca...