VendorsSAPnetweaver_application_server_abap750
Vulnerabilities

SAP NetWeaver Application Server ABAP 750

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

60CVEs
CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.
Published 2023-02-14 · Modified
6.1EPSS 0.003
CVE-2026-27682
Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published 2026-05-12 · Analyzed
6.1EPSS 0.003
CVE-2026-34257
Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
Published 2026-04-14 · Analyzed
6.1EPSS 0.003
CVE-2021-33664
SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Published 2021-06-09 · Modified
5.4EPSS 0.005
CVE-2023-23854
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Published 2023-02-14 · Modified
5.4EPSS 0.005
CVE-2024-21738
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Published 2024-01-09 · Modified
5.4EPSS 0.003
CVE-2021-40495
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
Published 2021-10-12 · Modified
5.3EPSS 0.011
CVE-2026-27688
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
5.0EPSS 0.003
CVE-2022-41212
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
Published 2022-11-08 · Modified
4.9EPSS 0.008
CVE-2021-40504
A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions.
Published 2021-11-10 · Modified
4.9EPSS 0.006
CVE-2022-41215
SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
Published 2022-11-08 · Modified
4.7EPSS 0.005
CVE-2021-40496
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Published 2021-10-12 · Modified
4.3EPSS 0.010
CVE-2020-6310
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Published 2020-08-12 · Modified
4.3EPSS 0.009
CVE-2020-6371
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
Published 2020-10-15 · Modified
4.3EPSS 0.009
CVE-2020-6299
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
Published 2020-08-12 · Modified
4.3EPSS 0.009
CVE-2021-42067
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.
Published 2022-01-14 · Modified
4.3EPSS 0.006
CVE-2026-24310
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
4.3EPSS 0.002
CVE-2020-6280
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
Published 2020-07-14 · Modified
4.0EPSS 0.009
CVE-2024-41728
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
CVE-2024-44114
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
← Prev2 / 2