SAP NetWeaver ABAP Platform是德国思爱普(SAP)公司的一个一体化技术平台。 SAP NetWeaver ABAP Platform 存在安全漏洞,该漏洞源于RFC协议验证不当,可能导致未经身份验证的攻击者发送特制RFC请求,利用内存管理逻辑错误导致内存损坏,对应用机密性、完整性和可用性造成高影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP NetWeaver AS ABAP and ABAP Platform | KRNL64NUC 7.22 |
affected |
7.22EXT |
affected | ||
KRNL64UC 7.22 |
affected | ||
722EXT |
affected | ||
7.53 |
affected | ||
KERNEL 7.22 |
affected | ||
7.54 |
affected | ||
7.77 |
affected | ||
| … +5 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver AS ABAP and ABAP Platform | KRNL64NUC 7.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44748 | 9.9 CRITICAL | XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform |
| CVE-2026-40128 | 9.0 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) |
| CVE-2026-44751 | 7.1 HIGH | Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform |
| CVE-2026-44754 | 6.6 MEDIUM | Missing caller identification check-in for ODP Data Replication APIs |
| CVE-2026-44744 | 6.5 MEDIUM | SQL Injection vulnerability in SAP S/4HANA |
| CVE-2026-44746 | 6.1 MEDIUM | Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Ser |
| CVE-2026-44757 | 4.7 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager |
| CVE-2026-44750 | 4.3 MEDIUM | Missing Authorization check in SAP MDG (Review Match Groups Application) |
| CVE-2026-44755 | 4.3 MEDIUM | Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform |
| CVE-2026-24315 | 4.2 MEDIUM | Path Traversal Vulnerability in SAP Fiori (launchpad) |
| CVE-2026-44743 | 3.7 LOW | Security Misconfiguration vulnerability in SAP Business Objects |
No comments yet