SAP

Netweaver Abap

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 12.05.2026 02:20:45
  • Zuletzt bearbeitet 12.05.2026 14:19:41

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered...

Medienbericht
  • EPSS 0.1%
  • Veröffentlicht 12.08.2025 02:10:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash ...

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 12.08.2025 02:10:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the...

  • EPSS 0.48%
  • Veröffentlicht 08.07.2025 06:57:25
  • Zuletzt bearbeitet 27.10.2025 16:51:37

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used...

  • EPSS 0.09%
  • Veröffentlicht 13.08.2024 04:15:07
  • Zuletzt bearbeitet 12.09.2024 14:39:03

Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This co...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 14.06.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:59:26

SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49,...

  • EPSS 0.15%
  • Veröffentlicht 14.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:25

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to ...

  • EPSS 0.42%
  • Veröffentlicht 12.04.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 06:56:57

SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal informat...

  • EPSS 0.36%
  • Veröffentlicht 09.02.2022 23:15:19
  • Zuletzt bearbeitet 21.11.2024 06:46:59

A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 7...

  • EPSS 0.58%
  • Veröffentlicht 09.02.2022 23:15:18
  • Zuletzt bearbeitet 21.11.2024 06:46:59

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently valid...