cbcvebase.

Sap Netweaver Application Server Abap vulnerabilities

86 known vulnerabilities affecting sap/netweaver_application_server_abap.

Total CVEs
86
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH18MEDIUM54LOW3

Vulnerabilities

Page 3 of 5
CVE-2021-27603P4MEDIUMCVSS 6.5v731v740+1 more2021-04-13
CVE-2021-27603 [MEDIUM] CVE-2021-27603: An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, a An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the SAP system.
nvd
CVE-2024-33001P4MEDIUMCVSS 6.5v740v2008_1_710+1 more2024-06-11
CVE-2024-33001 [MEDIUM] CWE-400 CVE-2024-33001: SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by cra SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitimate users causing high impact on availability of the a
nvd
CVE-2023-41366P4MEDIUMCVSS 5.3vkernel_7.22vkernel_7.53+13 more2023-11-14
CVE-2023-41366 [MEDIUM] CWE-497 CVE-2023-41366: Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KE Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the uninten
nvd
CVE-2026-27688P4MEDIUMCVSS 5.0v700v701+14 more2026-03-10
CVE-2026-27688 [MEDIUM] CWE-862 CVE-2026-27688: Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data,
nvd
CVE-2023-24522P4MEDIUMCVSS 6.1v700v701+3 more2023-02-14
CVE-2023-24522 [MEDIUM] CWE-79 CVE-2023-24522: Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700 Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the inte
nvd
CVE-2023-23858P4MEDIUMCVSS 6.1v740v750+7 more2023-02-14
CVE-2023-23858 [MEDIUM] CWE-79 CVE-2023-23858: Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 75 Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensi
nvd
CVE-2022-26102P4MEDIUMCVSS 5.4v700v701+2 more2022-03-10
CVE-2022-26102 [MEDIUM] CWE-862 CVE-2022-26102: Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 7 Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized for that transaction. A successful exploitation could expose information
nvd
CVE-2023-23859P4MEDIUMCVSS 6.1v740v750+9 more2023-02-14
CVE-2023-23859 [MEDIUM] CWE-79 CVE-2023-23859: SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
nvd
CVE-2023-23860P4MEDIUMCVSS 6.1v740v750+9 more2023-02-14
CVE-2023-23860 [MEDIUM] CWE-601 CVE-2023-23860: SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack.
nvd
CVE-2026-34257P4MEDIUMCVSS 6.1v700v701+12 more2026-04-14
CVE-2026-34257 [MEDIUM] CWE-601 CVE-2026-34257: Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated a Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft malicious URL that, if accessed by a victim, they could be redirected to the page controlled by the attacker. This causes low impact on confidentiality and integrity of the application with no impact on availability.
nvd
CVE-2021-33663P4MEDIUMCVSS 5.3vkernel_7.22vkernel_7.49+21 more2021-06-09
CVE-2021-33663 [MEDIUM] CVE-2021-33663: SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.2 SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83,7.84, allows an unauthorized attacker to insert cleartext commands due to improper restriction of I/O buffering into encrypted SMTP sessions ove
nvd
CVE-2024-41732P4MEDIUMCVSS 5.4v755v756+8 more2024-08-13
CVE-2024-41732 [MEDIUM] CWE-284 CVE-2024-41732: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability
nvd
CVE-2021-27611P4MEDIUMCVSS 6.7v700v701+3 more2021-05-11
CVE-2021-27611 [MEDIUM] CWE-94 CVE-2021-27611: SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to injec SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service.
nvd
CVE-2023-25614P4MEDIUMCVSS 6.1v700v701+11 more2023-02-14
CVE-2023-25614 [MEDIUM] CWE-79 CVE-2023-25614: SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which leads to a limited impact on the c
nvd
CVE-2023-23853P4MEDIUMCVSS 6.1v700v702+12 more2023-02-14
CVE-2023-23853 [MEDIUM] CWE-601 CVE-2023-23853: An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the v
nvd
CVE-2021-33684P4MEDIUMCVSS 5.3v7.21v7.21ext+11 more2021-07-14
CVE-2021-33684 [MEDIUM] CWE-787 CVE-2021-33684: SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.77, 7.81, 7.84, allows an attacker to send overlong content
nvd
CVE-2024-24740P4MEDIUMCVSS 5.3vkernel_7.53vkernel_7.54+6 more2024-02-13
CVE-2024-24740 [MEDIUM] CWE-732 CVE-2024-24740: SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.8 SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain conditions, allows an attacker to access information which could otherwise be restricted with low impact on confidentiality of the application.
nvd
CVE-2026-27682P4MEDIUMCVSS 6.1v700v701+14 more2026-05-12
CVE-2026-27682 [MEDIUM] CWE-79 CVE-2026-27682: Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is processed during web page generatio
nvd
CVE-2023-23854P4MEDIUMCVSS 5.4v700v701+6 more2023-02-14
CVE-2023-23854 [MEDIUM] CWE-862 CVE-2023-23854: SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
nvd
CVE-2022-35294P4MEDIUMCVSS 5.4v7.22extv7.49+9 more2022-09-13
CVE-2022-35294 [MEDIUM] CWE-79 CVE-2022-35294: An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWe An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected u
nvd
Sap Netweaver Application Server Abap vulnerabilities | cvebase