VYPR

NetWeaver Application Server for ABAP

by SAP

CVEs (135)

  • CVE-2020-26818HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing…

  • CVE-2020-6296HigAug 12, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the…

  • CVE-2019-0257HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of…

  • CVE-2025-23186HigApr 8, 2025
    risk 0.55cvss 8.5epss 0.01

    In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited…

  • CVE-2024-54198HigDec 10, 2024
    risk 0.55cvss 8.5epss 0.01

    In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited…

  • CVE-2026-0506HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data…

  • CVE-2025-42976HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.00

    SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component.…

  • CVE-2020-26832HigDec 9, 2020
    risk 0.50cvss 7.6epss 0.02

    SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC…

  • CVE-2023-40308HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.01

    SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any…

  • CVE-2022-22543HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information,…

  • CVE-2022-22540HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of…

  • CVE-2021-38181HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2021-33677HigJul 14, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure.

  • CVE-2021-21446HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.

  • CVE-2020-6240HigMay 12, 2020
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service

  • CVE-2023-26459HigMar 14, 2023
    risk 0.48cvss 7.4epss 0.00

    Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to…

  • CVE-2021-44235MedDec 14, 2021
    risk 0.44cvss 6.7epss 0.00

    Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction…

  • CVE-2021-27611MedMay 11, 2021
    risk 0.44cvss 6.7epss 0.00

    SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial…

  • CVE-2026-40135MedMay 12, 2026
    risk 0.42cvss 6.5epss 0.01

    An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This…

  • CVE-2026-24316MedMar 10, 2026
    risk 0.42cvss 6.4epss 0.00

    SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to…

Page 2 of 7