VendorsSAPnetweaver_application_server_abap700
Vulnerabilities

SAP NetWeaver Application Server ABAP 700

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2021-40496
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Published 2021-10-12 · Modified
4.3EPSS 0.010
CVE-2020-6310
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Published 2020-08-12 · Modified
4.3EPSS 0.009
CVE-2024-41728
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
← Prev2 / 2