SAP

Netweaver Application Server Abap

83 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 16.06.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:58:17

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper ...

  • EPSS 0.24%
  • Veröffentlicht 09.06.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 06:09:18

SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti...

  • EPSS 0.19%
  • Veröffentlicht 09.06.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 06:09:18

SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attack...

  • EPSS 0.24%
  • Veröffentlicht 09.06.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 06:09:18

SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • EPSS 0.25%
  • Veröffentlicht 09.06.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:48:28

SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a maliciou...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 09.06.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 05:48:26

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauth...

  • EPSS 0.11%
  • Veröffentlicht 11.05.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:58:17

SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwri...

  • EPSS 0.45%
  • Veröffentlicht 13.04.2021 19:15:15
  • Zuletzt bearbeitet 21.11.2024 05:58:16

An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes there...

  • EPSS 0.53%
  • Veröffentlicht 12.01.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:48:23

SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the ...

  • EPSS 0.3%
  • Veröffentlicht 09.12.2020 17:15:31
  • Zuletzt bearbeitet 21.11.2024 05:20:22

SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (X...