CVE-2021-33663
- EPSS 0.19%
- Veröffentlicht 09.06.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:09:18
SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attack...
CVE-2021-33665
- EPSS 0.24%
- Veröffentlicht 09.06.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:09:18
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti...
CVE-2021-21490
- EPSS 0.25%
- Veröffentlicht 09.06.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:48:28
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a maliciou...
CVE-2021-21473
- EPSS 0.48%
- Veröffentlicht 09.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:26
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauth...
CVE-2021-27611
- EPSS 0.11%
- Veröffentlicht 11.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:17
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwri...
CVE-2021-27603
- EPSS 0.51%
- Veröffentlicht 13.04.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:58:16
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes there...
CVE-2021-21446
- EPSS 0.53%
- Veröffentlicht 12.01.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:48:23
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the ...
CVE-2020-26835
- EPSS 0.3%
- Veröffentlicht 09.12.2020 17:15:31
- Zuletzt bearbeitet 21.11.2024 05:20:22
SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (X...
CVE-2020-26832
- EPSS 0.5%
- Veröffentlicht 09.12.2020 17:15:31
- Zuletzt bearbeitet 21.11.2024 05:20:21
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileg...
CVE-2020-26819
- EPSS 0.38%
- Veröffentlicht 10.11.2020 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:20:20
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.