SAP NetWeaver Application Server和SAP ABAP Platform都是德国思爱普(SAP)公司的产品。SAP NetWeaver Application Server是一款应用程序服务器。SAP ABAP Platform是一个基于 ABAP 的 SAP 解决方案。 SAP NetWeaver Application Server和SAP ABAP Platform存在授权问题漏洞,该漏洞源于允许经过身份验证的攻击者通过利用不正确的身份验证检查来获取对系统的非法访问,从而
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver Application Server for ABAP and ABAP Platform | KRNL64NUC 7.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0066 | 9.9 CRITICAL | Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Inter |
| CVE-2025-0063 | 8.8 HIGH | SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2025-0061 | 8.7 HIGH | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform |
| CVE-2025-0069 | 7.8 HIGH | DLL Hijacking vulnerability in SAPSetup |
| CVE-2025-0058 | 6.5 MEDIUM | Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow |
| CVE-2025-0060 | 6.5 MEDIUM | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform |
| CVE-2025-0067 | 6.3 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server Java |
| CVE-2025-0055 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP GUI for Windows |
| CVE-2025-0056 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP GUI for Java |
| CVE-2025-0059 | 6.0 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (application |
| CVE-2025-0053 | 5.3 MEDIUM | Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP |
| CVE-2025-0057 | 4.8 MEDIUM | Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application) |
| CVE-2025-0068 | 4.3 MEDIUM | Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Ser |
No comments yet