VendorsSAPabap_platform754
Vulnerabilities

SAP ABAP Platform 754

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-44231
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Published 2021-12-14 · Modified
9.8EPSS 0.013
CVE-2020-6318
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Published 2020-09-09 · Modified
9.1EPSS 0.058
CVE-2023-25615
SQL Injection vulnerability in SAP ABAP Platform
Published 2023-03-14 · Modified
6.8EPSS 0.005
CVE-2020-6299
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
Published 2020-08-12 · Modified
4.3EPSS 0.009