VendorsSAPnetweaver_application_server_abapkernel_7.77
Vulnerabilities

SAP NetWeaver Application Server ABAP kernel_7.77

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-40309
Missing Authorization check in SAP CommonCryptoLib
Published 2023-09-12 · Modified
9.8EPSS 0.009
CVE-2023-40308
Memory Corruption vulnerability in SAP CommonCryptoLib
Published 2023-09-12 · Modified
7.5EPSS 0.008
CVE-2023-35874
Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
Published 2023-07-11 · Modified
7.4EPSS 0.004
CVE-2022-39799
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Published 2022-09-13 · Modified
6.1EPSS 0.005
CVE-2021-33663
SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions over the network which can partially impact the integrity of the application.
Published 2021-06-09 · Modified
5.8EPSS 0.008
CVE-2021-33665
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Published 2021-06-09 · Modified
5.4EPSS 0.005
CVE-2023-41366
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Published 2023-11-14 · Modified
5.3EPSS 0.006
CVE-2024-24740
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)
Published 2024-02-13 · Modified
5.3EPSS 0.004