SAP NetWeaver AS是德国思爱普(SAP)公司的一款SAP网络应用服务器。它不仅能提供网络服务,且还是SAP软件的基本平台。 SAP NetWeaver AS for ABAP存在安全漏洞,该漏洞源于访问控制薄弱,允许攻击者访问受限制的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) | SAP_BASIS 700 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0070 | 9.9 CRITICAL | Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform |
| CVE-2025-0063 | 8.8 HIGH | SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2025-0061 | 8.7 HIGH | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform |
| CVE-2025-0069 | 7.8 HIGH | DLL Hijacking vulnerability in SAPSetup |
| CVE-2025-0058 | 6.5 MEDIUM | Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow |
| CVE-2025-0060 | 6.5 MEDIUM | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform |
| CVE-2025-0067 | 6.3 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server Java |
| CVE-2025-0055 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP GUI for Windows |
| CVE-2025-0056 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP GUI for Java |
| CVE-2025-0059 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (application |
| CVE-2025-0053 | 5.3 MEDIUM | Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP |
| CVE-2025-0057 | 4.8 MEDIUM | Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application) |
| CVE-2025-0068 | 4.3 MEDIUM | Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Ser |
No comments yet