VYPR

NetWeaver Application Server for ABAP

by SAP

CVEs (76)

  • CVE-2025-42975MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing…

  • CVE-2025-42945MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited…

  • CVE-2025-42942MedAug 12, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the…

  • CVE-2025-42956MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page…

  • CVE-2025-42981MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's…

  • CVE-2025-42969MedJul 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On…

  • CVE-2025-26659MedMar 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful…

  • CVE-2025-25242MedMar 11, 2025
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its…

  • CVE-2024-45279MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be…

  • CVE-2024-32733MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker…

  • CVE-2023-23853MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious…

  • CVE-2018-2470MedOct 9, 2018
    risk 0.40cvss 6.1epss 0.01

    In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2025-0059MedJan 14, 2025
    risk 0.39cvss 6.0epss 0.00

    Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able…

  • CVE-2023-35874MedJul 11, 2023
    risk 0.39cvss 6.0epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some…

  • CVE-2025-42908MedOct 14, 2025
    risk 0.35cvss 5.4epss 0.00

    Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This…

  • CVE-2025-42936MedAug 12, 2025
    risk 0.35cvss 5.4epss 0.00

    The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This…

  • CVE-2024-47586MedNov 12, 2024
    risk 0.35cvss 5.3epss 0.04

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the…

  • CVE-2022-35294MedSep 13, 2022
    risk 0.35cvss 5.4epss 0.00

    An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure…

  • CVE-2022-29610MedMay 11, 2022
    risk 0.35cvss 5.4epss 0.00

    SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

  • CVE-2022-26102MedMar 10, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized…