SAP Vulnerabilities and Affected Products
Vulnerabilities associated with NetWeaver AS ABAP (BSP Framework).
Products
Clear product- NetWeaver19 vulnerabilities
- NetWeaver AS for ABAP and ABAP Platform7 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform5 vulnerabilities
- SAP Fiori Client5 vulnerabilities
- commerce_cloud4 vulnerabilities
- Solution Manager4 vulnerabilities
- BusinessObjects Business Intelligence Platform (Web Services)3 vulnerabilities
- NetWeaver Application Server for ABAP and ABAP Platform3 vulnerabilities
- NetWeaver AS ABAP (BSP Framework)3 vulnerabilities
- NetWeaver AS for Java3 vulnerabilities
- SAP BusinessObjects Business Intelligence3 vulnerabilities
- SAP HANA extended application services3 vulnerabilities
- SAP Internet Graphics Server (IGS)3 vulnerabilities
- Application Interface Framework (Message Dashboard)2 vulnerabilities
- Business Planning and Consolidation2 vulnerabilities
- business_objects_business_intelligence_platform2 vulnerabilities
- commerce_hycom2 vulnerabilities
- CRM (WebClient UI)2 vulnerabilities
- NetWeaver Process Integration2 vulnerabilities
- netweaver_application_server_java2 vulnerabilities
- SAP Adaptive Server Enterprise (ASE)2 vulnerabilities
- SAP BusinessObjects Business Intelligence Suite2 vulnerabilities
- SAP Enterprise Financial Services2 vulnerabilities
- SAP HANA2 vulnerabilities
- SAP NetWeaver AS Java (ServerCore)2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-25614MEDIUM | SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which leads to a limited impact on the confidentiality and the integrity of the application. CWE-79Feb 14, 2023 | CVSS6.1v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24522MEDIUM | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application. CWE-79Feb 14, 2023 | CVSS6.1v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24521MEDIUM | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application. CWE-79Feb 14, 2023 | CVSS6.1v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |