VendorsSAPnetweaver_application_server_abap752
Vulnerabilities

SAP NetWeaver Application Server ABAP 752

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2020-6275
SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious server. Furthermore, if NTLM is setup the attacker can compromise confidentiality, integrity and availability of the SAP database.
Published 2020-06-10 · Modified
9.8EPSS 0.014
CVE-2021-27610
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.
Published 2021-06-16 · Modified
9.8EPSS 0.013
CVE-2021-44231
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
Published 2021-12-14 · Modified
9.8EPSS 0.013
CVE-2023-0014
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-01-10 · Modified
9.8EPSS 0.007
CVE-2023-27269
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27500
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27501
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2021-38178
The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the confidentiality, integrity, and availability of the system and its data.
Published 2021-10-12 · Modified
8.8EPSS 0.013
CVE-2020-26818
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
Published 2020-11-10 · Modified
8.8EPSS 0.012
CVE-2020-26819
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
Published 2020-11-10 · Modified
8.8EPSS 0.009
CVE-2022-29611
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published 2022-05-11 · Modified
8.8EPSS 0.008
CVE-2026-0506
Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Published 2026-01-13 · Analyzed
8.1EPSS 0.003
CVE-2021-33678
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.
Published 2021-07-14 · Modified
7.5EPSS 0.025
CVE-2021-21446
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
Published 2021-01-12 · Modified
7.5EPSS 0.014
CVE-2020-6240
SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service
Published 2020-05-12 · Modified
7.5EPSS 0.014
CVE-2022-22540
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.
Published 2022-02-09 · Modified
7.5EPSS 0.012
CVE-2021-38181
SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Published 2021-10-12 · Modified
7.5EPSS 0.011
CVE-2023-26459
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
7.4EPSS 0.004
CVE-2021-44235
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.
Published 2021-12-14 · Modified
7.2EPSS 0.003
CVE-2026-40135
OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2026-05-12 · Analyzed
6.5EPSS 0.019
CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
Published 2021-06-09 · Modified
6.5EPSS 0.012
CVE-2020-6270
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
Published 2020-06-10 · Modified
6.5EPSS 0.008
CVE-2023-27270
Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-28763
Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-04-11 · Modified
6.5EPSS 0.006
CVE-2023-25618
Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-37492
Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
Published 2023-08-08 · Modified
6.5EPSS 0.005
CVE-2026-24309
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
6.4EPSS 0.002
CVE-2026-24316
Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
6.4EPSS 0.002
CVE-2020-26835
SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
Published 2020-12-09 · Modified
6.1EPSS 0.008
CVE-2021-21490
SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all information with the same rights as the target user.
Published 2021-06-09 · Modified
6.1EPSS 0.006
CVE-2023-23859
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-25614
SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which leads to a limited impact on the confidentiality and the integrity of the application.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-23858
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensitive data. This could cause a limited impact on confidentiality and integrity of the application.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-0013
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-01-10 · Modified
6.1EPSS 0.004
CVE-2023-23860
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.
Published 2023-02-14 · Modified
6.1EPSS 0.003
CVE-2026-27682
Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published 2026-05-12 · Analyzed
6.1EPSS 0.003
CVE-2026-34257
Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
Published 2026-04-14 · Analyzed
6.1EPSS 0.003
CVE-2021-33664
SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Published 2021-06-09 · Modified
5.4EPSS 0.005
CVE-2023-23854
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published 2023-02-14 · Modified
5.4EPSS 0.005
1 / 2Next →