cbcvebase.

Sap Netweaver Application Server Abap vulnerabilities

86 known vulnerabilities affecting sap/netweaver_application_server_abap.

Total CVEs
86
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH18MEDIUM54LOW3

Vulnerabilities

Page 1 of 5
CVE-2022-22536P1CRITICALCVSS 10.0KEVPoCv7.22v7.49+15 more2022-02-09
CVE-2022-22536 [CRITICAL] CWE-444 CVE-2022-22536: SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Con SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the vi
nvd
CVE-2026-0488P2CRITICALCVSS 9.9v7002026-02-10
CVE-2026-0488 [CRITICAL] CWE-862 CVE-2026-0488: An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a ge An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
nvd
CVE-2023-49581P2CRITICALCVSS 9.4v700v731+2 more2023-12-12
CVE-2023-49581 [CRITICAL] CWE-89 CVE-2023-49581: SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information whi SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on
nvd
CVE-2023-27269P3CRITICALCVSS 9.6v700v701+12 more2023-03-14
CVE-2023-27269 [CRITICAL] CWE-22 CVE-2023-27269: SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can be read but potentially critic
nvd
CVE-2023-27501P3CRITICALCVSS 9.6v700v701+12 more2023-03-14
CVE-2023-27501 [CRITICAL] CWE-22 CVE-2023-27501: SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this attack, no data can be read but po
nvd
CVE-2023-40309P3CRITICALCVSS 9.8v7.22extvkernel_7.22+15 more2023-09-12
CVE-2023-40309 [CRITICAL] CWE-863 CVE-2023-40309: SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as r
nvd
CVE-2021-40499P3CRITICALCVSS 9.8v7.70v7.70_pi+1 more2021-10-12
CVE-2021-40499 [CRITICAL] CWE-94 CVE-2021-40499: Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Se Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
nvd
CVE-2020-6275P3CRITICALCVSS 9.8v700v701+11 more2020-06-10
CVE-2020-6275 [CRITICAL] CWE-918 CVE-2020-6275: SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into authenticating with the malicious
nvd
CVE-2021-27610P3CRITICALCVSS 9.8v700v701+10 more2021-06-16
CVE-2021-27610 [CRITICAL] CWE-287 CVE-2021-27610: SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.
nvd
CVE-2021-38178P3HIGHCVSS 8.8v700v701+12 more2021-10-12
CVE-2021-38178 [HIGH] CVE-2021-38178: The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 7 The software logistics system of SAP NetWeaver AS ABAP and ABAP Platform versions - 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, enables a malicious user to transfer ABAP code artifacts or content, by-passing the established quality gates. By this vulnerability malicious code can reach quality and production, and can compromise the co
nvd
CVE-2026-0506P3HIGHCVSS 8.1v700v701+13 more2026-01-13
CVE-2026-0506 [HIGH] CWE-862 CVE-2026-0506: Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, result
nvd
CVE-2021-44231P3CRITICALCVSS 9.8v701v740+8 more2021-12-14
CVE-2021-44231 [CRITICAL] CWE-94 CVE-2021-44231: Internally used text extraction reports allow an attacker to inject code that can be executed by the Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
nvd
CVE-2020-6296P3HIGHCVSS 8.8v700v701+9 more2020-08-12
CVE-2020-6296 [HIGH] CVE-2020-6296: SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 75 SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
nvd
CVE-2020-26819P3HIGHCVSS 8.8v731v740+7 more2020-11-10
CVE-2020-26819 [HIGH] CVE-2020-26819: SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows a SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
nvd
CVE-2019-0257P3HIGHCVSS 8.8≥ 7.0, ≤ 7.02≥ 7.50, ≤ 7.53+3 more2019-02-15
CVE-2019-0257 [HIGH] CWE-862 CVE-2019-0257: Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, fro Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
nvd
CVE-2022-29611P3HIGHCVSS 8.8v700v701+15 more2022-05-11
CVE-2022-29611 [HIGH] CWE-862 CVE-2022-29611: SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization c SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
nvd
CVE-2023-0014P3CRITICALCVSS 9.8v700v701+14 more2023-01-10
CVE-2023-0014 [CRITICAL] CWE-294 CVE-2023-0014: SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerabi
nvd
CVE-2026-40135P3MEDIUMCVSS 6.5v700v701+13 more2026-05-12
CVE-2026-40135 [MEDIUM] CWE-77 CVE-2026-40135: An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and AB An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially
nvd
CVE-2020-26818P3HIGHCVSS 8.8v731v740+7 more2020-11-10
CVE-2020-26818 [HIGH] CWE-862 CVE-2020-26818: SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows a SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
nvd
CVE-2023-27500P3HIGHCVSS 8.1v700v701+11 more2023-03-14
CVE-2023-27500 [HIGH] CWE-22 CVE-2023-27500: An attacker with non-administrative authorizations can exploit a directory traversal flaw in program An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.
nvd