SAP ABAP Platform和SAP NetWeaver Application Server ABAP都是德国思爱普(SAP)公司的产品。SAP ABAP Platform是一个基于 ABAP 的 SAP 解决方案。SAP NetWeaver Application Server ABAP是一个运行和开发基于ABAP语言的应用程序的平台。 SAP NetWeaver Application Server ABAP和SAP ABAP Platform存在跨站脚本漏洞,该漏洞源于未验证攻击者可注入恶意
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | SAP_BASIS 740 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-42967 | 9.9 CRITICAL | Code Injection vulnerability in SAP S/4HANA and SAP SCM (Characteristic Propagation) |
| CVE-2025-42963 | 9.1 CRITICAL | Insecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer ) |
| CVE-2025-42980 | 9.1 CRITICAL | Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network |
| CVE-2025-42964 | 9.1 CRITICAL | Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration |
| CVE-2025-42966 | 9.1 CRITICAL | Insecure Deserialization vulnerability in SAP NetWeaver (XML Data Archiving Service) |
| CVE-2025-42953 | 8.1 HIGH | Missing Authorization check in SAP NetWeaver Application Server for ABAP |
| CVE-2025-42959 | 8.1 HIGH | Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476 |
| CVE-2025-42952 | 7.7 HIGH | Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis |
| CVE-2025-42992 | 6.9 MEDIUM | Multiple Privilege Escalation Vulnerabilities in SAPCAR |
| CVE-2025-43001 | 6.9 MEDIUM | Multiple Privilege Escalation Vulnerabilities in SAPCAR |
| CVE-2025-42981 | 6.1 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server ABAP |
| CVE-2025-42962 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Business Warehouse (Business Explorer Web |
| CVE-2025-42985 | 6.1 MEDIUM | Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench |
| CVE-2025-42970 | 5.8 MEDIUM | Directory Traversal vulnerability in SAPCAR |
| CVE-2025-42979 | 5.6 MEDIUM | Insecure Key & Secret Management vulnerability in SAP GUI for Windows |
| CVE-2025-42973 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report) |
| CVE-2025-42968 | 5.0 MEDIUM | Missing Authorization check in SAP NetWeaver (RFC enabled function module) |
| CVE-2025-42961 | 4.9 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server for ABAP |
| CVE-2025-42974 | 4.3 MEDIUM | Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) |
| CVE-2025-42986 | 4.3 MEDIUM | Missing Authorization check in SAP NetWeaver and ABAP Platform |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet