cbcvebase.

Sap Netweaver Application Server Abap vulnerabilities

86 known vulnerabilities affecting sap/netweaver_application_server_abap.

Total CVEs
86
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH18MEDIUM54LOW3

Vulnerabilities

Page 2 of 5
CVE-2022-41214P3HIGHCVSS 8.7v700v731+4 more2022-11-08
CVE-2022-41214 [HIGH] CWE-20 CVE-2022-41214: Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
nvd
CVE-2022-22540P3HIGHCVSS 7.5v700v701+11 more2022-02-09
CVE-2022-22540 [HIGH] CWE-89 CVE-2022-22540: SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754 SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.
nvd
CVE-2023-35874P3HIGHCVSS 7.4vkernel_7.22vkernel_7.53+12 more2023-07-11
CVE-2023-35874 [HIGH] CWE-306 CVE-2023-35874: SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities th
nvd
CVE-2023-26459P3HIGHCVSS 7.4v700v701+12 more2023-03-14
CVE-2023-26459 [HIGH] CWE-918 CVE-2023-26459: Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 7 Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavai
nvd
CVE-2021-21446P3HIGHCVSS 7.5v740v750+5 more2021-01-12
CVE-2021-21446 [HIGH] CVE-2021-21446: SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacke SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
nvd
CVE-2020-26832P3HIGHCVSS 7.6v2011_1_620v2011_1_640+6 more2020-12-09
CVE-2020-26832 [HIGH] CWE-862 CVE-2020-26832: SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_71 SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing a
nvd
CVE-2023-40308P3HIGHCVSS 7.5v7.22extvkernel_7.22+15 more2023-09-12
CVE-2023-40308 [HIGH] CWE-787 CVE-2023-40308: SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to a SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
nvd
CVE-2020-6240P3HIGHCVSS 7.5v700v710+7 more2020-05-12
CVE-2020-6240 [HIGH] CVE-2020-6240: SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service
nvd
CVE-2021-38181P3HIGHCVSS 7.5v700v701+11 more2021-10-12
CVE-2021-38181 [HIGH] CVE-2021-38181: SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2026-24309P3MEDIUMCVSS 6.4v700v701+13 more2026-03-10
CVE-2026-24309 [MEDIUM] CWE-862 CVE-2026-24309: Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated at Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerabilit
nvd
CVE-2021-33677P3HIGHCVSS 7.5v700v702+6 more2021-07-14
CVE-2021-33677 [HIGH] CVE-2021-33677: SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expo SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure.
nvd
CVE-2026-24316P3MEDIUMCVSS 6.4v740v750+9 more2026-03-10
CVE-2026-24316 [MEDIUM] CWE-918 CVE-2026-24316: SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with potentially sensitive internal endpoints, resulting in
nvd
CVE-2021-33678P3MEDIUMCVSS 6.5v75av75b+15 more2021-07-14
CVE-2021-33678 [MEDIUM] CWE-95 CVE-2021-33678: A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710 A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system c
nvd
CVE-2021-21473P3MEDIUMCVSS 6.3v700v702+11 more2021-06-09
CVE-2021-21473 [MEDIUM] CWE-862 CVE-2021-21473: SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752 SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.
nvd
CVE-2023-37492P3MEDIUMCVSS 6.5v700v701+13 more2023-08-08
CVE-2023-37492 [MEDIUM] CWE-863 CVE-2023-37492: SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 793, SAP_BASIS 804, does not perform necessary authorization checks for an auth
nvd
CVE-2023-28763P3MEDIUMCVSS 6.5v740v750+8 more2023-04-11
CVE-2023-28763 [MEDIUM] CWE-400 CVE-2023-28763: SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.
nvd
CVE-2020-6270P4MEDIUMCVSS 6.5v75av75b+9 more2020-06-10
CVE-2020-6270 [MEDIUM] CWE-862 CVE-2020-6270: SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75 SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
nvd
CVE-2021-44235P4MEDIUMCVSS 6.7v700v701+13 more2021-12-14
CVE-2021-44235 [MEDIUM] CWE-78 CVE-2021-44235: Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operat
nvd
CVE-2023-27270P4MEDIUMCVSS 6.5v700v701+12 more2023-03-14
CVE-2023-27270 [MEDIUM] CWE-400 CVE-2023-27270: SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources s
nvd
CVE-2023-25618P4MEDIUMCVSS 6.5v700v701+12 more2023-03-14
CVE-2023-25618 [MEDIUM] CWE-400 CVE-2023-25618: SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters which will consume the server's res
nvd
Sap Netweaver Application Server Abap vulnerabilities | cvebase