CVE-2026-0507
- EPSS 0.88%
- Veröffentlicht 13.01.2026 01:15:36
- Zuletzt bearbeitet 13.01.2026 14:03:18
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If proces...
CVE-2025-42901
- EPSS 0.04%
- Veröffentlicht 14.10.2025 00:17:23
- Zuletzt bearbeitet 14.10.2025 19:36:29
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentialit...
CVE-2020-6262
- EPSS 0.79%
- Veröffentlicht 12.05.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:24
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control...