VendorsSAPnetweaver_application_server_abap7.54
Vulnerabilities

SAP NetWeaver Application Server ABAP 7.54

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-39799
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Published 2022-09-13 · Modified
6.1EPSS 0.005
CVE-2023-27499
Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
Published 2023-04-11 · Modified
6.1EPSS 0.004
CVE-2022-35294
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
Published 2022-09-13 · Modified
5.4EPSS 0.005