Loading HuntDB...

ABAP Platform

87 Versions 25 CVEs

Versions

710

SINGLE_NUMBER 2 CVEs

< 731

OTHER 11 CVEs

< 785

OTHER 1 CVE

KRNL64UC 7.49

OTHER 1 CVE

< 7.81

OTHER 1 CVE

= 753

OTHER 1 CVE

= 751

OTHER 1 CVE

7.22EXT

OTHER 4 CVEs

711

SINGLE_NUMBER 2 CVEs

< KERNEL 8.04

OTHER 1 CVE

= 757

OTHER 1 CVE

< 784

OTHER 1 CVE

740

SINGLE_NUMBER 3 CVEs

700

SINGLE_NUMBER 2 CVEs

< KRNL64UC 8.04

OTHER 1 CVE

< 700

OTHER 8 CVEs

753

SINGLE_NUMBER 2 CVEs

= 754

OTHER 1 CVE

756

SINGLE_NUMBER 2 CVEs

KRNL64UC 7.22

OTHER 2 CVEs

< 752

OTHER 9 CVEs

7.49

MAJOR_MINOR 4 CVEs

= 750

OTHER 3 CVEs

< 710

OTHER 4 CVEs

787

SINGLE_NUMBER 2 CVEs

< KRNL64NUC 7.21

OTHER 1 CVE

= 789

OTHER 3 CVEs

< KRNL32UC 7.21

OTHER 1 CVE

7.81

MAJOR_MINOR 5 CVEs

< 756

OTHER 5 CVEs

< 702

OTHER 10 CVEs

< KRNL32NUC 7.21

OTHER 1 CVE

= 790

OTHER 1 CVE

750

SINGLE_NUMBER 3 CVEs

< 7.84

OTHER 1 CVE

= 731

OTHER 3 CVEs

SAPHOSTAGENT 7.22

OTHER 2 CVEs

7.85

MAJOR_MINOR 5 CVEs

KRNL64NUC 7.49

OTHER 1 CVE

7.86

MAJOR_MINOR 5 CVEs

< 711

OTHER 4 CVEs

KRNL64UC 8.04

OTHER 2 CVEs

7.87

MAJOR_MINOR 5 CVEs

< 740

OTHER 13 CVEs

< 7.49

OTHER 1 CVE

< 754

OTHER 9 CVEs

KERNEL 7.49

OTHER 1 CVE

< 804

OTHER 2 CVEs

KRNL64NUC 7.22

OTHER 4 CVEs

< 7.21EXT

OTHER 1 CVE

= 755

OTHER 1 CVE

< 750

OTHER 13 CVEs

8.04

MAJOR_MINOR 3 CVEs

788

SINGLE_NUMBER 1 CVE

730

SINGLE_NUMBER 2 CVEs

< 786

OTHER 1 CVE

755

SINGLE_NUMBER 2 CVEs

< DEV

DEV 1 CVE

KERNEL 7.22

OTHER 4 CVEs

< 730

OTHER 9 CVEs

752

SINGLE_NUMBER 2 CVEs

7.22

MAJOR_MINOR 3 CVEs

731

SINGLE_NUMBER 2 CVEs

< 7.21

OTHER 1 CVE

= 702

OTHER 1 CVE

< 7.53

OTHER 1 CVE

< 755

OTHER 10 CVEs

= 701

OTHER 1 CVE

= 752

OTHER 1 CVE

< 701

OTHER 8 CVEs

< 753

OTHER 10 CVEs

751

SINGLE_NUMBER 2 CVEs

754

SINGLE_NUMBER 2 CVEs

< 7.22EXT

OTHER 1 CVE

701

SINGLE_NUMBER 2 CVEs

= 700

OTHER 3 CVEs

< 7.22

OTHER 1 CVE

7.53

MAJOR_MINOR 4 CVEs

SAP_ROUTER 7.53

OTHER 1 CVE

< 751

OTHER 10 CVEs

= 740

OTHER 3 CVEs

< 7.77

OTHER 1 CVE

7.77

MAJOR_MINOR 5 CVEs

= 804

OTHER 2 CVEs

= 756

OTHER 1 CVE

702

SINGLE_NUMBER 2 CVEs

7.88

MAJOR_MINOR 4 CVEs

Recent CVEs

CVE-2022-41215

SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

MEDIUM Nov 08, 2022

CVE-2022-41212

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.

MEDIUM Nov 08, 2022

CVE-2022-41214

Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.

HIGH Nov 08, 2022

CVE-2022-29614

SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, - on Unix systems, s-bit helper program sapuxuserchk, can be abused physically resulting in a privilege escalation of an attacker leading to low impact on confidentiality and integrity, but a profound impact on availability.

UNKNOWN Jun 14, 2022

CVE-2022-29612

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.

UNKNOWN Jun 14, 2022

CVE-2022-27668

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53, 7.22, from a remote client, for example stopping the SAProuter, that could highly impact systems availability.

UNKNOWN Jun 14, 2022

CVE-2022-29616

SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.

UNKNOWN May 11, 2022

CVE-2022-22536

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

UNKNOWN Feb 09, 2022