VendorsSAPnetweaver_application_server_abap7.85
Vulnerabilities

SAP NetWeaver Application Server ABAP 7.85

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-22536
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Published 2022-02-09 · Analyzed
10.0KEV1 PoCEPSS 0.979
CVE-2022-39799
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Published 2022-09-13 · Modified
6.1EPSS 0.005
CVE-2023-27499
Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
Published 2023-04-11 · Modified
6.1EPSS 0.004
CVE-2022-35294
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
Published 2022-09-13 · Modified
5.4EPSS 0.005