Sap Se Sap Netweaver Application Server Abap vulnerabilities
25 known vulnerabilities affecting sap_se/sap_netweaver_application_server_abap.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM21
Vulnerabilities
Page 2 of 2
CVE-2025-27437P4MEDIUMCVSS 4.3vSAP_BASIS 700vSAP_BASIS 701+12 more2025-04-08
CVE-2025-27437 [MEDIUM] CWE-862 CVE-2025-27437: A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver A
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and with no effect on availability.
nvd
CVE-2025-26653P4MEDIUMCVSS 4.7vKRNL64NUC 7.22v7.22EXT+8 more2025-04-08
CVE-2025-26653 [MEDIUM] CWE-79 CVE-2025-26653: SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading t
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script gets executed, potentially compro
nvd
CVE-2026-27680P4MEDIUMCVSS 4.3vSAP_UI 758v8162026-05-14
CVE-2026-27680 [MEDIUM] CWE-276 CVE-2026-27680: Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allow
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, whi
nvd
CVE-2025-0068P4MEDIUMCVSS 4.3vSAP_BASIS 700vSAP_BASIS 701+12 more2025-01-14
CVE-2025-0068 [MEDIUM] CWE-862 CVE-2025-0068: An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authori
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
nvd
CVE-2020-6371P4MEDIUMCVSS 4.3fixed in 710fixed in 711+4 more2020-10-15
CVE-2020-6371 [MEDIUM] CVE-2020-6371: User enumeration vulnerability can be exploited to get a list of user accounts and personal user inf
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
nvd
← Previous2 / 2