SAP

Abap Platform

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 12.08.2025 02:08:28
  • Zuletzt bearbeitet 12.08.2025 14:25:33

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read ...

  • EPSS 0.04%
  • Veröffentlicht 08.07.2025 00:38:32
  • Zuletzt bearbeitet 08.07.2025 16:18:14

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low i...

  • EPSS 0.13%
  • Veröffentlicht 08.07.2025 00:36:41
  • Zuletzt bearbeitet 08.07.2025 16:18:14

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payl...

  • EPSS 0.16%
  • Veröffentlicht 08.07.2025 00:35:03
  • Zuletzt bearbeitet 08.07.2025 16:18:14

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...

Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 13.05.2025 00:16:51
  • Zuletzt bearbeitet 13.05.2025 19:35:25

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...

  • EPSS 0.06%
  • Veröffentlicht 11.02.2025 01:15:11
  • Zuletzt bearbeitet 18.02.2025 18:15:34

The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction ...

  • EPSS 0.08%
  • Veröffentlicht 10.09.2024 05:15:12
  • Zuletzt bearbeitet 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module targeting specific parameters, the specific targeted u...

  • EPSS 0.14%
  • Veröffentlicht 10.09.2024 05:15:11
  • Zuletzt bearbeitet 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.

  • EPSS 0.09%
  • Veröffentlicht 10.09.2024 03:15:03
  • Zuletzt bearbeitet 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impa...

  • EPSS 0.09%
  • Veröffentlicht 10.09.2024 03:15:02
  • Zuletzt bearbeitet 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confiden...