cbcvebase.

Sap Netweaver Application Server Abap vulnerabilities

86 known vulnerabilities affecting sap/netweaver_application_server_abap.

Total CVEs
86
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL11HIGH18MEDIUM54LOW3

Vulnerabilities

Page 5 of 5
CVE-2020-6299P4MEDIUMCVSS 4.3v740v750+4 more2020-08-12
CVE-2020-6299 [MEDIUM] CVE-2020-6299: SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
nvd
CVE-2021-42067P4MEDIUMCVSS 4.3v701v702+12 more2022-01-14
CVE-2021-42067 [MEDIUM] CVE-2021-42067: In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 75 In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.
nvd
CVE-2020-6371P4MEDIUMCVSS 4.3v710v711+4 more2020-10-15
CVE-2020-6371 [MEDIUM] CVE-2020-6371: User enumeration vulnerability can be exploited to get a list of user accounts and personal user inf User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
nvd
CVE-2024-44114P4LOWCVSS 2.7v702v731+11 more2024-09-10
CVE-2024-44114 [LOW] CWE-863 CVE-2024-44114: SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to exec SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.
nvd
CVE-2020-6280P4LOWCVSS 2.7v731v740+1 more2020-07-14
CVE-2020-6280 [LOW] CVE-2020-6280: SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2024-41728P4LOWCVSS 2.7v700v701+13 more2024-09-10
CVE-2024-41728 [LOW] CWE-862 CVE-2024-41728: Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allo Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view these objects.
nvd
Sap Netweaver Application Server Abap vulnerabilities | cvebase