VendorsSAPnetweaver_application_server_abap752
Vulnerabilities

SAP NetWeaver Application Server ABAP 752

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2024-21738
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Published 2024-01-09 · Modified
5.4EPSS 0.003
CVE-2021-40495
There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
Published 2021-10-12 · Modified
5.3EPSS 0.011
CVE-2026-27688
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
5.0EPSS 0.003
CVE-2021-40504
A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions.
Published 2021-11-10 · Modified
4.9EPSS 0.006
CVE-2021-40496
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Published 2021-10-12 · Modified
4.3EPSS 0.010
CVE-2021-42067
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.
Published 2022-01-14 · Modified
4.3EPSS 0.006
CVE-2026-24310
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
4.3EPSS 0.002
CVE-2024-41728
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
CVE-2024-44114
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
← Prev2 / 2