Sap Se Sap Netweaver Application Server Abap vulnerabilities
26 known vulnerabilities affecting sap_se/sap_netweaver_application_server_abap.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM22
Vulnerabilities
Page 2 of 2
CVE-2026-44760P4MEDIUMCVSS 4.7vSAP_BASIS 700vSAP_BASIS 701+16 more2026-07-14
CVE-2026-44760 [MEDIUM] CWE-79 CVE-2026-44760: Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages frame
Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal
nvd
CVE-2024-47593P4MEDIUMCVSS 4.3vKRNL64UC 7.53vKERNEL 7.53+5 more2024-11-12
CVE-2024-47593 [MEDIUM] CWE-276 CVE-2024-47593: SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTM
nvd
CVE-2025-26653P4MEDIUMCVSS 4.7vKRNL64NUC 7.22v7.22EXT+8 more2025-04-08
CVE-2025-26653 [MEDIUM] CWE-79 CVE-2025-26653: SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading t
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script gets executed, potentially compro
nvd
CVE-2026-27680P4MEDIUMCVSS 4.3vSAP_UI 758v8162026-05-14
CVE-2026-27680 [MEDIUM] CWE-276 CVE-2026-27680: Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allow
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result, the issue has a low impact on confidentiality, whi
nvd
CVE-2025-0068P4MEDIUMCVSS 4.3vSAP_BASIS 700vSAP_BASIS 701+12 more2025-01-14
CVE-2025-0068 [MEDIUM] CWE-862 CVE-2025-0068: An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authori
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
nvd
CVE-2020-6371P4MEDIUMCVSS 4.3fixed in 710fixed in 711+4 more2020-10-15
CVE-2020-6371 [MEDIUM] CVE-2020-6371: User enumeration vulnerability can be exploited to get a list of user accounts and personal user inf
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
nvd
← Previous2 / 2