VYPR

Sap Netweaver As For Abap And Abap Platform

by SAP

CVEs (12)

  • CVE-2025-0066CriJan 14, 2025
    risk 0.64cvss 9.9epss 0.01

    Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an…

  • CVE-2023-27500CriMar 14, 2023
    risk 0.62cvss 9.6epss 0.01

    An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.

  • CVE-2023-27501HigMar 14, 2023
    risk 0.57cvss 8.7epss 0.01

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available…

  • CVE-2023-26459HigMar 14, 2023
    risk 0.48cvss 7.4epss 0.00

    Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to…

  • CVE-2023-28763MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it…

  • CVE-2023-25618MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can…

  • CVE-2023-23860MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or…

  • CVE-2023-23859MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.

  • CVE-2023-23858MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and…

  • CVE-2023-0013MedJan 10, 2023
    risk 0.40cvss 6.1epss 0.00

    The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On…

  • CVE-2023-29108MedApr 11, 2023
    risk 0.33cvss 5.0epss 0.00

    The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources.

  • CVE-2021-42067MedJan 14, 2022
    risk 0.28cvss 4.3epss 0.01

    In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to…