SAP_SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP NetWeaver Application Server ABAP and ABAP Platform.
Products
Clear product- SAP BusinessObjects Business Intelligence Platform22 vulnerabilities
- SAP NetWeaver Application Server for ABAP and ABAP Platform16 vulnerabilities
- SAP NetWeaver Application Server ABAP12 vulnerabilities
- SAP NetWeaver Application Server for ABAP12 vulnerabilities
- SAP Business AI Platform (Approuter)11 vulnerabilities
- SAP NetWeaver Application Server ABAP and ABAP Platform10 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform9 vulnerabilities
- SAP Commerce Cloud8 vulnerabilities
- SAP GUI for Windows8 vulnerabilities
- SAP NetWeaver Application Server Java8 vulnerabilities
- SAP Business Connector7 vulnerabilities
- SAP CRM WebClient UI7 vulnerabilities
- SAP Enable Now6 vulnerabilities
- SAP Fiori App (Intercompany Balance Reconciliation)6 vulnerabilities
- SAP NetWeaver Enterprise Portal6 vulnerabilities
- SAP Manufacturing Integration and Intelligence5 vulnerabilities
- SAP Supplier Relationship Management (Live Auction Cockpit)5 vulnerabilities
- SAP Web Dispatcher5 vulnerabilities
- SAP Commerce4 vulnerabilities
- SAP Financial Consolidation4 vulnerabilities
- SAP Host Agent4 vulnerabilities
- SAP NetWeaver4 vulnerabilities
- SAP NetWeaver AS Java4 vulnerabilities
- SAP Solution Manager4 vulnerabilities
- SAPCAR4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58236MEDIUM | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP PlatformSAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high impact on availability. CWE-78Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0509CRITICAL | Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP PlatformSAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application. CWE-862Feb 10, 2026 | CVSS9.6v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0506HIGH | Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP PlatformDue to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected. CWE-862Jan 13, 2026 | CVSS8.1v3.1 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-42969MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformSAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can access or modify sensitive information within the scope of victim's web browser, with no impact on availability of the application. CWE-79Jul 8, 2025 | CVSS6.1v3.1 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31329MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformSAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integr… CWE-141May 13, 2025 | CVSS6.2v3.1 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-41734MEDIUM | Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP PlatformDue to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability. CWE-862Aug 13, 2024 | CVSS4.3v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33006CRITICAL | File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformAn unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. CWE-434May 14, 2024 | CVSS9.6v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32733MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformDue to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application CWE-79May 14, 2024 | CVSS6.1v3.1 | EPSS0.404% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-49581MEDIUM | SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformSAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability. | CVSS4.1v3.1 | EPSS0.506% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41366MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformUnder certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of t… CWE-497Nov 14, 2023 | CVSS5.3v3.1 | EPSS0.586% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |