Sap Netweaver As Abap Business Server Pages vulnerabilities

10 known vulnerabilities affecting sap/netweaver_as_abap_business_server_pages.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM10

Vulnerabilities

Page 1 of 1
CVE-2023-29185MEDIUMCVSS 6.5v700v701+11 more2023-04-11
CVE-2023-29185 [MEDIUM] CWE-400 CVE-2023-29185: SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network w
nvd
CVE-2023-24521MEDIUMCVSS 6.1v700v701+11 more2023-02-14
CVE-2023-24521 [MEDIUM] CWE-79 CVE-2023-24521: Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 7 Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on
nvd
CVE-2023-24529MEDIUMCVSS 6.1v7.00v7.01+12 more2023-02-14
CVE-2023-24529 [MEDIUM] CWE-79 CVE-2023-24529: Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 73 Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user se
nvd
CVE-2020-6324MEDIUMCVSS 6.1v700v701+10 more2020-09-09
CVE-2020-6324 [MEDIUM] CWE-79 CVE-2020-6324: SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,7 SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to Reflected Cross Site Scripting.
nvd
CVE-2020-6246MEDIUMCVSS 6.1v700v701+9 more2020-06-10
CVE-2020-6246 [MEDIUM] CWE-79 CVE-2020-6246: SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2020-6213MEDIUMCVSS 6.1v700v701+9 more2020-04-24
CVE-2020-6213 [MEDIUM] CWE-79 CVE-2020-6213: SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs.
nvd
CVE-2020-6215MEDIUMCVSS 6.1v700v701+9 more2020-04-14
CVE-2020-6215 [MEDIUM] CWE-601 CVE-2020-6215: SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
nvd
CVE-2020-6217MEDIUMCVSS 6.1v700v701+9 more2020-04-14
CVE-2020-6217 [MEDIUM] CWE-79 CVE-2020-6217: SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2020-6229MEDIUMCVSS 6.1v75av75b+14 more2020-04-14
CVE-2020-6229 [MEDIUM] CWE-79 CVE-2020-6229: SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710 SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2020-6205MEDIUMCVSS 6.1v7.00v7.01+11 more2020-03-10
CVE-2020-6205 [MEDIUM] CWE-79 CVE-2020-6205: SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.1 SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user a
nvd