VendorsSAPnetweaver_application_server_abap754
Vulnerabilities

SAP NetWeaver Application Server ABAP 754

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2026-27688
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
5.0EPSS 0.003
CVE-2021-40504
A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions.
Published 2021-11-10 · Modified
4.9EPSS 0.006
CVE-2021-40496
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.
Published 2021-10-12 · Modified
4.3EPSS 0.010
CVE-2020-6299
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
Published 2020-08-12 · Modified
4.3EPSS 0.009
CVE-2021-42067
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.
Published 2022-01-14 · Modified
4.3EPSS 0.006
CVE-2026-24310
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
4.3EPSS 0.002
CVE-2024-41728
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
CVE-2024-44114
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
← Prev2 / 2