VendorsSAPnetweaver_application_server_abap757
Vulnerabilities

SAP NetWeaver Application Server ABAP 757

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2023-0014
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-01-10 · Modified
9.8EPSS 0.007
CVE-2023-27500
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27269
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2023-27501
Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
9.6EPSS 0.010
CVE-2026-0506
Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Published 2026-01-13 · Analyzed
8.1EPSS 0.003
CVE-2023-26459
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
7.4EPSS 0.004
CVE-2026-40135
OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2026-05-12 · Analyzed
6.5EPSS 0.019
CVE-2023-25618
Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-27270
Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-03-14 · Modified
6.5EPSS 0.006
CVE-2023-28763
Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-04-11 · Modified
6.5EPSS 0.006
CVE-2023-37492
Missing Authorization check in SAP NetWeaver AS ABAP and ABAP Platform
Published 2023-08-08 · Modified
6.5EPSS 0.005
CVE-2026-24309
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
6.4EPSS 0.002
CVE-2026-24316
Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
6.4EPSS 0.002
CVE-2023-23859
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-25614
SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which leads to a limited impact on the confidentiality and the integrity of the application.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-23858
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensitive data. This could cause a limited impact on confidentiality and integrity of the application.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-0013
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2023-01-10 · Modified
6.1EPSS 0.004
CVE-2023-23860
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack.
Published 2023-02-14 · Modified
6.1EPSS 0.004
CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.
Published 2023-02-14 · Modified
6.1EPSS 0.003
CVE-2026-27682
Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published 2026-05-12 · Analyzed
6.1EPSS 0.003
CVE-2026-34257
Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
Published 2026-04-14 · Analyzed
6.1EPSS 0.003
CVE-2023-40624
Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)
Published 2023-09-12 · Modified
5.5EPSS 0.004
CVE-2024-41732
Improper Access Control in SAP Netweaver Application Server ABAP
Published 2024-08-13 · Analyzed
5.4EPSS 0.003
CVE-2024-21738
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
Published 2024-01-09 · Modified
5.4EPSS 0.003
CVE-2026-27688
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
5.0EPSS 0.003
CVE-2026-24310
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2026-03-10 · Analyzed
4.3EPSS 0.002
CVE-2024-41728
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003
CVE-2024-44114
Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-09-10 · Analyzed
2.7EPSS 0.003