cbcvebase.

Sap Netweaver Application Server Abap vulnerabilities

86 known vulnerabilities affecting sap/netweaver_application_server_abap.

Total CVEs
86
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH18MEDIUM54LOW3

Vulnerabilities

Page 4 of 5
CVE-2023-40624P4MEDIUMCVSS 5.4v702v731+5 more2023-09-12
CVE-2023-40624 [MEDIUM] CWE-79 CVE-2023-40624: SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, S SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
nvd
CVE-2021-21490P4MEDIUMCVSS 6.1v75av75f+8 more2021-06-09
CVE-2021-21490 [MEDIUM] CWE-79 CVE-2021-21490: SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerability, through which a malicious user can access data relating to the current session and use it to impersonate a user and access all
nvd
CVE-2022-41212P4MEDIUMCVSS 4.9v700v731+4 more2022-11-08
CVE-2022-41212 [MEDIUM] CWE-22 CVE-2022-41212: Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
nvd
CVE-2019-0321P4MEDIUMCVSS 6.1v7.312019-07-10
CVE-2019-0321 [MEDIUM] CWE-79 CVE-2019-0321: ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2022-39799P4MEDIUMCVSS 6.1v7.54v7.81+3 more2022-09-13
CVE-2022-39799 [MEDIUM] CWE-79 CVE-2022-39799: An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML w An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
nvd
CVE-2023-27499P4MEDIUMCVSS 6.1v7.22v7.53+8 more2023-04-11
CVE-2023-27499 [MEDIUM] CWE-79 CVE-2023-27499: SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7 SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the atta
nvd
CVE-2023-0013P4MEDIUMCVSS 6.1v702v731+9 more2023-01-10
CVE-2023-0013 [MEDIUM] CWE-79 CVE-2023-0013: The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 75 The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and
nvd
CVE-2021-40495P4MEDIUMCVSS 5.3v740v750+5 more2021-10-12
CVE-2021-40495 [MEDIUM] CVE-2021-40495: There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP an There are multiple Denial-of Service vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755. An unauthorized attacker can use the public SICF service /sap/public/bc/abap to reduce the performance of SAP NetWeaver Application Server ABAP and ABAP Platform.
nvd
CVE-2022-29610P4MEDIUMCVSS 5.4v753v754+2 more2022-05-11
CVE-2022-29610 [MEDIUM] CWE-79 CVE-2022-29610: SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
nvd
CVE-2021-33664P4MEDIUMCVSS 5.4v31v702+5 more2021-06-09
CVE-2021-33664 [MEDIUM] CWE-79 CVE-2021-33664: SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 7 SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2024-21738P4MEDIUMCVSS 5.4v79v700+14 more2024-01-09
CVE-2024-21738 [MEDIUM] CWE-79 CVE-2024-21738: SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled i SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
nvd
CVE-2022-41215P4MEDIUMCVSS 4.7v700v731+3 more2022-11-08
CVE-2022-41215 [MEDIUM] CWE-601 CVE-2022-41215: SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
nvd
CVE-2021-40496P4MEDIUMCVSS 4.3v700v701+12 more2021-10-12
CVE-2021-40496 [MEDIUM] CWE-668 CVE-2021-40496: SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 7 SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is no
nvd
CVE-2020-26835P4MEDIUMCVSS 6.1v740v750+4 more2020-12-09
CVE-2020-26835 [MEDIUM] CWE-79 CVE-2020-26835: SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL wh SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2021-33665P4MEDIUMCVSS 5.4vkernel_7.49vkernel_7.53+6 more2021-06-09
CVE-2021-33665 [MEDIUM] CWE-79 CVE-2021-33665: SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2026-24310P4MEDIUMCVSS 4.3v702v731+11 more2026-03-10
CVE-2026-24310 [MEDIUM] CWE-862 CVE-2026-24310: Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated at Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on the integrity and availability.
nvd
CVE-2021-40504P4MEDIUMCVSS 4.9v700v701+13 more2021-11-10
CVE-2021-40504 [MEDIUM] CWE-863 CVE-2021-40504: A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 70 A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions.
nvd
CVE-2020-6310P4MEDIUMCVSS 4.3v700v701+9 more2020-08-12
CVE-2020-6310 [MEDIUM] CVE-2020-6310: Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
nvd
CVE-2026-27680P4MEDIUMCVSS 4.3v758v8162026-05-14
CVE-2026-27680 [MEDIUM] CWE-276 CVE-2026-27680: Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allow Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, whi
nvd
CVE-2024-41734P4MEDIUMCVSS 4.3vsap_basis_700vsap_basis_701+13 more2024-08-13
CVE-2024-41734 [MEDIUM] CWE-862 CVE-2024-41734: Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an au Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
nvd
Sap Netweaver Application Server Abap vulnerabilities | cvebase