Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SAP NetWeaver Application Server for ABAP — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in SAP NetWeaver Application Server for ABAP, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in the SAP NetWeaver Application Server for ABAP, a critical enterprise middleware component. It aggregates security weaknesses categorized by common weakness enumeration standards to provide a structured overview of potential risks associated with this specific product version. The content compiles reported security flaws, ranging from remote code execution and privilege escalation to information disclosure and buffer overflow issues. This database covers vulnerabilities identified and published from the earliest available records up to the most recent disclosures, ensuring a comprehensive historical perspective. Users can explore these entries to track vendor advisories and patch releases from SAP, helping organizations stay informed about emerging threats. The page allows security professionals and system administrators to understand specific weakness classes affecting ABAP-based environments, facilitating better risk assessment and remediation planning. By examining the detailed descriptions and technical contexts of these flaws, readers can gain insights into how such vulnerabilities are typically exploited. Additionally, the resource serves as a lookup tool for the product's vulnerability history, enabling teams to audit past incidents and evaluate their current security posture against known issues. This information supports compliance requirements and helps prioritize patching efforts based on the severity and relevance of each weakness to the deployed SAP infrastructure.

Vendor: SAP

CVE IDTitleCVSSSeverityPublished
CVE-2026-58246 Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform CWE-497 4.3 Medium2026-07-28
CVE-2026-27688 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 5.0 Medium2026-03-10
CVE-2026-24316 Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP CWE-918 6.4 Medium2026-03-10
CVE-2026-24310 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 3.5 Low2026-03-10
CVE-2026-24309 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 6.4 Medium2026-03-10
CVE-2025-42882 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 4.3 Medium2025-11-11
CVE-2025-42908 Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP CWE-352 5.4 Medium2025-10-14
CVE-2025-42942 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP CWE-79 6.1 Medium2025-08-12
CVE-2025-42936 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-266 5.4 Medium2025-08-12
CVE-2025-42961 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 4.9 Medium2025-07-08
CVE-2025-42953 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 8.1 High2025-07-08
CVE-2025-42989 Missing Authorization check in SAP NetWeaver Application Server for ABAP CWE-862 9.6 Critical2025-06-10
CVE-2022-26102 SAP NetWeaver Application Server 安全漏洞 CWE-862 5.4 -2022-03-08
CVE-2018-2470 SAP NetWeaver Application Server for ABAP 跨站脚本漏洞 6.1 -2018-10-09

All 14 known CVE vulnerabilities affecting SAP NetWeaver Application Server for ABAP with full Chinese analysis, references, and POCs where available.