Vulnerabilities
Summary — last 7 days
New vulnerabilities2,712▼ 359 vs. last week
Critical / high1,261▼ 231 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)213▼ 109 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.2) | 1.2% | — | SAP Advanced Business Application Programming Platform Kernel | 8/14/2019 | 6/17/2026 | SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without… | |
| Modified | Critical (9.8) | 1.6% | — | SAP Advanced Business Application Programming Platform KernelSAP Advanced Business Application Programming Platform Krnl32nucSAP Advanced Business Application Programming Platform Krnl32ucSAP Advanced Business Application Programming Platform Krnl64nuc+1 | 6/12/2019 | 6/17/2026 | FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or… | |
| Modified | Medium (6.5) | 1.4% | — | SAP Advanced Business Application Programming PlatformSAP Advanced Business Application Programming ServerSAP Kernel | 3/12/2019 | 6/17/2026 | ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.21 or 7.22, that is ABAP Server 7.00 to 7.31 and Kernel 7.45, 7.49 or 7.53, that is ABAP Server 7.40… | |
| Modified | High (8.8) | 1.4% | — | SAP Advanced Business Application Programming Platform KernelSAP Advanced Business Application Programming Platform Krnl32nucSAP Advanced Business Application Programming Platform Krnl32ucSAP Advanced Business Application Programming Platform Krnl64nuc+1 | 3/12/2019 | 6/17/2026 | ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT,… | |
| Modified | Medium (4.9) | 2.1% | — | SAP Advanced Business Application Programming Platform KernelSAP Advanced Business Application Programming Platform Krnl32nucSAP Advanced Business Application Programming Platform Krnl32ucSAP Advanced Business Application Programming Platform Krnl64nuc+1 | 2/15/2019 | 6/17/2026 | SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49,KRNL64UC 7.21, 7.21EXT,… | |
| Modified | High (8.1) | 1.7% | — | SAP Advanced Business Application Programming Platform KernelSAP Advanced Business Application Programming Platform Krnl64nucSAP Advanced Business Application Programming Platform Krnl64uc | 2/15/2019 | 6/17/2026 | SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where business user achieves access to the full SAP Menu, that is 'Easy Access Menu'. The situation can be… | |
| Modified | High (7.2) | 1.5% | — | SAP Advanced Business Application Programming | 11/13/2018 | 6/17/2026 | In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for customer is used. By implementing such transaction code a malicious user may execute unauthorized transaction functionality. | |
| Modified | Critical (9.9) | 4.0% | — | PWC Ace-advanced Business Application Programming | 12/10/2016 | 6/17/2026 | PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report. |