S

Sap Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Sap products.

6 known CVE vulnerabilities tracked

Critical
0
High
0
Medium
5
Low
1
None
0

Vulnerabilities By Year

Products Affected

All Sap CVEs

CVE-2026-40135
6.5 medium

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of un

Netweaver Application Server Abap May 12, 2026
CVE-2026-27682
4.7 medium

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the i

Netweaver Application Server Abap May 12, 2026
CVE-2026-27688
5.0 medium

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially es

Netweaver Application Server Abap Mar 10, 2026
CVE-2026-24316
6.4 medium

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with pot

Netweaver Application Server Abap Mar 10, 2026
CVE-2026-24310
3.5 low

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality w

Netweaver Application Server Abap Mar 10, 2026
CVE-2026-24309
6.4 medium

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced sy

Netweaver Application Server Abap Mar 10, 2026