SAP

Abap Platform

24 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 12.08.2025 02:08:28
  • Last modified 12.08.2025 14:25:33

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read ...

  • EPSS 0.04%
  • Published 08.07.2025 00:38:32
  • Last modified 08.07.2025 16:18:14

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low i...

  • EPSS 0.13%
  • Published 08.07.2025 00:36:41
  • Last modified 08.07.2025 16:18:14

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payl...

  • EPSS 0.16%
  • Published 08.07.2025 00:35:03
  • Last modified 08.07.2025 16:18:14

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...

Media report
  • EPSS 0.06%
  • Published 13.05.2025 00:16:51
  • Last modified 13.05.2025 19:35:25

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...

  • EPSS 0.06%
  • Published 11.02.2025 01:15:11
  • Last modified 18.02.2025 18:15:34

The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction ...

  • EPSS 0.08%
  • Published 10.09.2024 05:15:12
  • Last modified 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module targeting specific parameters, the specific targeted u...

  • EPSS 0.14%
  • Published 10.09.2024 05:15:11
  • Last modified 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.

  • EPSS 0.09%
  • Published 10.09.2024 03:15:03
  • Last modified 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impa...

  • EPSS 0.09%
  • Published 10.09.2024 03:15:02
  • Last modified 10.09.2024 12:09:50

The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confiden...