CVE-2021-33663
- EPSS 0.19%
- Published 09.06.2021 14:15:10
- Last modified 21.11.2024 06:09:18
SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attack...
CVE-2021-33665
- EPSS 0.24%
- Published 09.06.2021 14:15:10
- Last modified 21.11.2024 06:09:18
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti...
CVE-2021-21490
- EPSS 0.25%
- Published 09.06.2021 14:15:08
- Last modified 21.11.2024 05:48:28
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a maliciou...
CVE-2021-21473
- EPSS 0.48%
- Published 09.06.2021 14:15:07
- Last modified 21.11.2024 05:48:26
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauth...
CVE-2021-27611
- EPSS 0.11%
- Published 11.05.2021 15:15:08
- Last modified 21.11.2024 05:58:17
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwri...
CVE-2021-27603
- EPSS 0.51%
- Published 13.04.2021 19:15:15
- Last modified 21.11.2024 05:58:16
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes there...
CVE-2021-21446
- EPSS 0.53%
- Published 12.01.2021 15:15:14
- Last modified 21.11.2024 05:48:23
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the ...
CVE-2020-26835
- EPSS 0.3%
- Published 09.12.2020 17:15:31
- Last modified 21.11.2024 05:20:22
SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (X...
CVE-2020-26832
- EPSS 0.5%
- Published 09.12.2020 17:15:31
- Last modified 21.11.2024 05:20:21
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileg...
CVE-2020-26819
- EPSS 0.38%
- Published 10.11.2020 17:15:14
- Last modified 21.11.2024 05:20:20
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.