VendorsSAPnetweaver_application_server_abapall versions
Vulnerabilities

SAP NetWeaver Application Server ABAP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

86CVEs
CVE-2022-22536
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Published 2022-02-09 · Analyzed
10.0KEV1 PoCEPSS 0.979
CVE-2026-0488
Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
Published 2026-02-10 · Analyzed
9.9EPSS 0.005
CVE-2020-6275
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.
Published 2020-06-10 · Modified
9.8EPSS 0.014
CVE-2021-27610
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.
Published 2021-06-16 · Modified
9.8EPSS 0.013
CVE-2021-44231
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Published 2021-12-14 · Modified
9.8EPSS 0.013
CVE-2021-40499
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Published 2021-10-12 · Modified
9.8EPSS 0.012
CVE-2023-40309
Missing Authorization check in SAP CommonCryptoLib
Published 2023-09-12 · Modified
9.8EPSS 0.009
CVE-2023-0014
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-01-10 · Modified
9.8EPSS 0.007
CVE-2023-27269
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27500
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27501
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-49581
SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Published 2023-12-12 · Modified
9.4EPSS 0.005
CVE-2019-0257
Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published 2019-02-15 · Modified
8.8EPSS 0.014
CVE-2020-6296
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
Published 2020-08-12 · Modified
8.8EPSS 0.013
CVE-2021-38178
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.
Published 2021-10-12 · Modified
8.8EPSS 0.013
CVE-2020-26818
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
Published 2020-11-10 · Modified
8.8EPSS 0.012
CVE-2020-26819
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
Published 2020-11-10 · Modified
8.8EPSS 0.009
CVE-2022-29611
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published 2022-05-11 · Modified
8.8EPSS 0.008
CVE-2022-41214
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
Published 2022-11-08 · Modified
8.7EPSS 0.008
CVE-2021-27611
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.
Published 2021-05-11 · Modified
8.2EPSS 0.003
CVE-2026-0506
Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Published 2026-01-13 · Analyzed
8.1EPSS 0.003
CVE-2020-26832
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.
Published 2020-12-09 · Modified
7.6EPSS 0.022
CVE-2021-33678
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.
Published 2021-07-14 · Modified
7.5EPSS 0.025
CVE-2021-21446
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
Published 2021-01-12 · Modified
7.5EPSS 0.014
CVE-2020-6240
SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service
Published 2020-05-12 · Modified
7.5EPSS 0.014
CVE-2022-22540
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.
Published 2022-02-09 · Modified
7.5EPSS 0.012
CVE-2021-38181
SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Published 2021-10-12 · Modified
7.5EPSS 0.011
CVE-2021-33677
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure.
Published 2021-07-14 · Modified
7.5EPSS 0.009
CVE-2023-40308
Memory Corruption vulnerability in SAP CommonCryptoLib
Published 2023-09-12 · Modified
7.5EPSS 0.008
CVE-2023-35874
Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
Published 2023-07-11 · Modified
7.4EPSS 0.004
CVE-2023-26459
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
7.4EPSS 0.004
CVE-2021-44235
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.
Published 2021-12-14 · Modified
7.2EPSS 0.003
CVE-2026-40135
OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2026-05-12 · Analyzed
6.5EPSS 0.019
CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
Published 2021-06-09 · Modified
6.5EPSS 0.012
CVE-2021-27603
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the SAP system.
Published 2021-04-13 · Modified
6.5EPSS 0.009
CVE-2020-6270
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
Published 2020-06-10 · Modified
6.5EPSS 0.008
CVE-2023-25618
Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-27270
Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-28763
Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-04-11 · Modified
6.5EPSS 0.006
CVE-2023-37492
Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
Published 2023-08-08 · Modified
6.5EPSS 0.005
1 / 3Next →