SAP
SAP Abap Platform: vulnerabilidades y CVE
SAP Abap Platform tiene 32 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses10
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76963 | Media (4.3) | 0.28% | — | 8 sept 2026 | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful… |
| CVE-2026-66767 | Alta (7.7) | 0.43% | — | 8 sept 2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking… |
| CVE-2026-58247 | Media (5.3) | 0.36% | — | 11 ago 2026 | SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on… |
| CVE-2026-58241 | Media (4.2) | 0.25% | — | 11 ago 2026 | SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific… |
| CVE-2026-58236 | Media (5.5) | 0.69% | — | 11 ago 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful… |
| CVE-2026-58246 | Media (4.3) | 0.24% | — | 28 jul 2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the… |
| CVE-2026-44748 | Crítica (9.9) | 0.32% | — | 9 jun 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in… |
| CVE-2026-27671 | Crítica (9.8) | 0.62% | — | 9 jun 2026 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors… |
| CVE-2026-40129 | Media (4.3) | 0.34% | — | 12 may 2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the… |
| CVE-2025-42902 | Media (5.3) | 0.37% | — | 14 oct 2025 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads… |
| CVE-2025-42949 | Media (4.9) | 0.32% | — | 12 ago 2025 | Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable… |
| CVE-2025-42935 | Media (4.1) | 0.13% | — | 12 ago 2025 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in… |
| CVE-2025-42969 | Media (6.1) | 0.23% | — | 8 jul 2025 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL… |
| CVE-2025-30015 | Media (4.1) | 0.26% | — | 8 abr 2025 | Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to… |
| CVE-2025-24872 | Media (4.3) | 0.26% | — | 11 feb 2025 | The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an… |
| CVE-2025-0070 | Crítica (9.9) | 0.70% | — | 14 ene 2025 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation.… |
| CVE-2024-47585 | Media (4.3) | 0.27% | — | 10 dic 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege… |
| CVE-2024-47586 | Media (5.3) | 3.5% | — | 12 nov 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will… |
| CVE-2024-32733 | Media (6.1) | 0.40% | — | 14 may 2024 | Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically… |
| CVE-2024-30218 | Media (6.5) | 0.53% | — | 9 abr 2024 | The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable… |
| CVE-2024-27900 | Media (5.3) | 0.39% | — | 12 mar 2024 | Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template… |
| CVE-2024-22131 | Alta (7.2) | 1.1% | — | 13 feb 2024 | In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the… |
| CVE-2023-29110 | Media (5.4) | 0.32% | — | 11 abr 2023 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of… |
| CVE-2023-29109 | Media (4.6) | 0.32% | — | 11 abr 2023 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can… |
| CVE-2023-25615 | Media (4.9) | 0.55% | — | 14 mar 2023 | Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database… |
| CVE-2021-44231 | Crítica (9.8) | 1.3% | — | 14 dic 2021 | Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
| CVE-2020-6318 | Alta (7.2) | 5.8% | — | 9 sept 2020 | A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and… |
| CVE-2020-6310 | Media (4.3) | 0.94% | — | 12 ago 2020 | Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to… |
| CVE-2020-6299 | Media (4.3) | 0.90% | — | 12 ago 2020 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure. |
| CVE-2020-6296 | Alta (8.8) | 1.3% | — | 12 ago 2020 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection.… |
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Netweaver Enterprise Portal · 29Internet Graphics Server · 28