Loading HuntDB...

ABAP Platform

74 Versions 27 CVEs

Versions

2008_1_710

OTHER 1 CVE

ST-PI 2008_1_700

OTHER 1 CVE

731

SINGLE_NUMBER 8 CVEs

SAP_BASIS 755

OTHER 10 CVEs

7.97

MAJOR_MINOR 1 CVE

KRNL64NUC 7.22EXT

OTHER 2 CVEs

KRNL64UC 7.53

OTHER 2 CVEs

KERNEL 7.92

OTHER 2 CVEs

SAP_BASIS 750

OTHER 11 CVEs

KERNEL 7.54

OTHER 3 CVEs

KRNL64UC 7.22EXT

OTHER 2 CVEs

9.13

MAJOR_MINOR 2 CVEs

SAP_BASIS 794

OTHER 1 CVE

SAP_BASIS 758

OTHER 9 CVEs

SAP_BASIS 753

OTHER 10 CVEs

SAP_BASIS 731

OTHER 9 CVEs

SAP_BASIS 796

OTHER 3 CVEs

KERNEL64UC 7.22EXT

OTHER 1 CVE

SAP_BASIS740

OTHER 1 CVE

7.93

MAJOR_MINOR 2 CVEs

SAP_BASIS 804

OTHER 1 CVE

751

SINGLE_NUMBER 9 CVEs

7.22EXT

OTHER 2 CVEs

KERNEL64NUC 7.22EXT

OTHER 1 CVE

KERNEL 7.77

OTHER 3 CVEs

KERNEL 722

OTHER 1 CVE

KERNEL 7.91

OTHER 1 CVE

SAP_BASIS 751

OTHER 9 CVEs

754

SINGLE_NUMBER 9 CVEs

KERNEL64UC 7.53

OTHER 1 CVE

740

SINGLE_NUMBER 10 CVEs

700

SINGLE_NUMBER 7 CVEs

9.12

MAJOR_MINOR 2 CVEs

SAP_BASIS 912

OTHER 1 CVE

750

SINGLE_NUMBER 9 CVEs

SAP_BASIS 756

OTHER 10 CVEs

701

SINGLE_NUMBER 7 CVEs

SAP_BASIS 754

OTHER 10 CVEs

7.89

MAJOR_MINOR 2 CVEs

SAP_BASIS 702

OTHER 9 CVEs

KERNEL 7.53

OTHER 3 CVEs

753

SINGLE_NUMBER 9 CVEs

KERNEL64NUC 7.22

OTHER 1 CVE

KERNEL 7.81

OTHER 1 CVE

KERNEL 7.93

OTHER 3 CVEs

SAP_BASIS 752

OTHER 10 CVEs

KRNL64NUC 722

OTHER 1 CVE

SAP_BASIS 795

OTHER 3 CVEs

912

SINGLE_NUMBER 8 CVEs

7.54

MAJOR_MINOR 2 CVEs

756

SINGLE_NUMBER 9 CVEs

KRNL64NUC 7.22

OTHER 3 CVEs

757

SINGLE_NUMBER 9 CVEs

SAP_BASIS 740

OTHER 11 CVEs

7.53

MAJOR_MINOR 2 CVEs

KRNL64UC 7.22

OTHER 4 CVEs

758

SINGLE_NUMBER 8 CVEs

SAP_BASIS 701

OTHER 9 CVEs

8.04

MAJOR_MINOR 2 CVEs

7.77

MAJOR_MINOR 2 CVEs

SAP_BASIS 757

OTHER 10 CVEs

9.14

MAJOR_MINOR 1 CVE

KERNEL 7.85

OTHER 3 CVEs

KERNEL 7.94

OTHER 1 CVE

KERNEL 7.89

OTHER 3 CVEs

SAP_BASIS731

OTHER 1 CVE

755

SINGLE_NUMBER 9 CVEs

SAP_BASIS750

OTHER 1 CVE

SAP_BASIS 793

OTHER 2 CVEs

702

SINGLE_NUMBER 8 CVEs

KERNEL64UC 7.22

OTHER 1 CVE

KERNEL 7.22

OTHER 4 CVEs

SAP_BASIS 700

OTHER 10 CVEs

752

SINGLE_NUMBER 9 CVEs

Recent CVEs

CVE-2025-0070

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

CRITICAL Jan 14, 2025

CVE-2024-47585

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.

MEDIUM Dec 10, 2024

CVE-2024-47586

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.

MEDIUM Nov 12, 2024

CVE-2024-41734

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

MEDIUM Aug 13, 2024

CVE-2024-33006

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. 

CRITICAL May 14, 2024

CVE-2024-32733

Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application

MEDIUM May 14, 2024

CVE-2024-30218

The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable impact on availability.

MEDIUM Apr 09, 2024

CVE-2023-49581

SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.

MEDIUM Dec 12, 2023

CVE-2023-37492

SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 793, SAP_BASIS 804, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could allow an attacker to read sensitive information which can be used in a subsequent serious attack.

MEDIUM Aug 08, 2023

CVE-2023-35874

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities that require user identity. An attacker can perform malicious actions over the network, extending the scope of impact, causing a limited impact on confidentiality, integrity and availability.

MEDIUM Jul 11, 2023