SAP

Abap Platform

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 08.09.2026 01:17:51
  • Zuletzt bearbeitet 09.09.2026 05:17:27

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow ...

  • EPSS 0.21%
  • Veröffentlicht 11.08.2026 00:17:06
  • Zuletzt bearbeitet 26.08.2026 19:00:14

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integri...

  • EPSS 0.38%
  • Veröffentlicht 11.08.2026 00:12:40
  • Zuletzt bearbeitet 26.08.2026 19:00:14

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacke...

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 09.06.2026 00:20:04
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to...

  • EPSS 0.31%
  • Veröffentlicht 12.08.2025 02:08:28
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read ...

  • EPSS 0.22%
  • Veröffentlicht 08.07.2025 00:38:32
  • Zuletzt bearbeitet 27.10.2025 16:55:48

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low i...

  • EPSS 0.22%
  • Veröffentlicht 08.07.2025 00:36:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payl...

  • EPSS 0.51%
  • Veröffentlicht 08.07.2025 00:35:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 13.05.2025 00:16:51
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...

  • EPSS 0.25%
  • Veröffentlicht 11.02.2025 01:15:11
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction ...