SAP NetWeaver Application Server是德国思爱普(SAP)公司的一款应用程序服务器。 SAP NetWeaver Application Server存在安全漏洞,该漏洞源于缺少授权检查,可能导致已验证攻击者滥用RFC函数执行ABAP系统中的表单例程,对完整性和可用性造成高影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | SAP_BASIS 700 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0501 | 9.9 CRITICAL | SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials � Gene |
| CVE-2026-0500 | 9.6 CRITICAL | Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation) |
| CVE-2026-0491 | 9.1 CRITICAL | Code Injection vulnerability in SAP Landscape Transformation |
| CVE-2026-0498 | 9.1 CRITICAL | Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise) |
| CVE-2026-0492 | 8.8 HIGH | Privilege escalation vulnerability in SAP HANA database |
| CVE-2026-0507 | 8.4 HIGH | OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RF |
| CVE-2026-0511 | 8.1 HIGH | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) |
| CVE-2026-0496 | 6.6 MEDIUM | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) |
| CVE-2026-0503 | 6.4 MEDIUM | Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP EHS Manag |
| CVE-2026-0499 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2026-0514 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Business Connector |
| CVE-2026-0495 | 5.1 MEDIUM | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) |
| CVE-2026-0513 | 4.7 MEDIUM | Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM C |
| CVE-2026-0497 | 4.3 MEDIUM | Missing Authorization check in Business Server Pages Application (Product Designer Web UI) |
| CVE-2026-0494 | 4.3 MEDIUM | Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation |
| CVE-2026-0493 | 4.3 MEDIUM | Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Rec |
| CVE-2026-0504 | 3.8 LOW | Insufficient Input Handling in JNDI Operations of SAP Identity Management |
| CVE-2026-0510 | 3.0 LOW | Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping |
No comments yet