SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP都是德国思爱普(SAP)公司的产品。SAP NetWeaver ABAP Platform是一个一体化技术平台。SAP NetWeaver Application Server for ABAP是一个核心应用服务器平台。 SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP存在代码注入
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Application Server ABAP for SAP NetWeaver and ABAP Platform | SAP_BASIS 740 |
affected |
SAP_BASIS 750 |
affected | ||
SAP_BASIS 751 |
affected | ||
SAP_BASIS 752 |
affected | ||
SAP_BASIS 753 |
affected | ||
SAP_BASIS 754 |
affected | ||
SAP_BASIS 755 |
affected | ||
SAP_BASIS 756 |
affected | ||
| … +3 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Application Server ABAP for SAP NetWeaver and ABAP Platform | SAP_BASIS 740 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34263 | 9.6 CRITICAL | Missing authentication check in SAP Commerce cloud configuration |
| CVE-2026-34260 | 9.6 CRITICAL | SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) |
| CVE-2026-34259 | 8.2 HIGH | OS Command Injection Vulnerability in SAP Forecasting & Replenishment |
| CVE-2026-40135 | 6.5 MEDIUM | OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP P |
| CVE-2026-40133 | 6.3 MEDIUM | Missing Authorization check in SAP S/4HANA Condition Maintenance |
| CVE-2026-40137 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUN |
| CVE-2026-0502 | 5.4 MEDIUM | Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform |
| CVE-2026-40132 | 5.4 MEDIUM | Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanc |
| CVE-2026-27682 | 4.7 MEDIUM | Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABA |
| CVE-2026-34258 | 4.7 MEDIUM | Content Spoofing vulnerability in SAPUI5 (Search UI) |
| CVE-2026-40136 | 4.3 MEDIUM | Denial of service (DoS) in SAP Financial Consolidation |
| CVE-2026-40134 | 4.3 MEDIUM | Missing Authorization Check in SAP Incentive and Commission Management |
| CVE-2026-40131 | 3.4 LOW | SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library |
No comments yet