VendorsSAPsap_basisall versions
Vulnerabilities

SAP SAP Basis

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2025-0066
Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)
Published 2025-01-14 · Analyzed
9.9EPSS 0.006
CVE-2024-34687
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application server for ABAP and ABAP Platform
Published 2024-05-14 · Analyzed
9.0EPSS 0.004
CVE-2025-0063
SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Published 2025-01-14 · Analyzed
8.8EPSS 0.007
CVE-2026-23687
XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
Published 2026-02-10 · Modified
8.8EPSS 0.005
CVE-2016-4551
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
Published 2016-10-05 · Modified
7.5EPSS 0.014
CVE-2025-23193
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP
Published 2025-02-11 · Analyzed
7.5EPSS 0.003
CVE-2025-0058
Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow
Published 2025-01-14 · Analyzed
6.5EPSS 0.003
CVE-2026-0484
Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
Published 2026-02-10 · Analyzed
6.5EPSS 0.003
CVE-2025-42956
Multiple vulnerabilities in SAP NetWeaver Application Server ABAP
Published 2025-07-08 · Analyzed
6.1EPSS 0.002
CVE-2025-42936
Missing Authorization check in SAP NetWeaver Application Server for ABAP
Published 2025-08-12 · Analyzed
5.4EPSS 0.002
CVE-2025-0053
Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2025-01-14 · Analyzed
5.3EPSS 0.003
CVE-2024-37180
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-07-09 · Analyzed
5.3EPSS 0.003
CVE-2026-24312
Missing authorization check in SAP Business Workflow
Published 2026-02-10 · Analyzed
5.2EPSS 0.002
CVE-2024-34689
[CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
Published 2024-07-09 · Modified
5.0EPSS 0.004
CVE-2025-42911
Missing Authorization check in SAP NetWeaver (Service Data Download)
Published 2025-09-09 · Analyzed
5.0EPSS 0.002
CVE-2024-39599
[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published 2024-07-09 · Analyzed
4.7EPSS 0.003
CVE-2025-42986
Missing Authorization check in SAP NetWeaver and ABAP Platform
Published 2025-07-08 · Analyzed
4.3EPSS 0.002
CVE-2025-42918
Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)
Published 2025-09-09 · Analyzed
4.3EPSS 0.002