Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SAP NetWeaver Application Server ABAP — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in SAP NetWeaver Application Server ABAP, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the vendor SAP, specifically for the product SAP NetWeaver Application Server ABAP, categorized by weakness type. It collects publicly disclosed security flaws associated with this enterprise middleware component, covering the historical range from its initial release through the most recent advisory updates. Readers can use this resource to track SAP security advisories, understand common weakness classes affecting the ABAP stack, and review the vulnerability history of the NetWeaver platform without needing to parse individual CVE records.

Vendor: SAP SE

CVE ID Title CVSS Severity Published
CVE-2026-66779 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP CWE-79 6.3 Medium 2026-08-11
CVE-2026-44747 Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP CWE-787 9.9 Critical 2026-07-14
CVE-2026-27680 CSS Injection vulnerability in SAP NetWeaver Application Server ABAP CWE-276 3.1 Low 2026-05-14
CVE-2026-34257 Open Redirect vulnerability in SAP NetWeaver Application Server ABAP CWE-601 6.1 Medium 2026-04-14
CVE-2025-42945 HTML Injection vulnerability in SAP NetWeaver Application Server ABAP CWE-94 6.1 Medium 2025-08-12
CVE-2025-42956 Multiple vulnerabilities in SAP NetWeaver Application Server ABAP CWE-79 6.1 Medium 2025-07-08
CVE-2025-42981 Multiple vulnerabilities in SAP NetWeaver Application Server ABAP CWE-601 6.1 Medium 2025-07-08
CVE-2025-23186 Mixed Dynamic RFC Destination vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP CWE-94 8.5 High 2025-04-08
CVE-2025-25242 Cross-Site Scripting (XSS) in SAP NetWeaver Application Server ABAP CWE-79 6.1 Medium 2025-03-11
CVE-2025-0068 Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP CWE-862 4.3 Medium 2025-01-14
CVE-2024-54198 Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP CWE-914 8.5 High 2024-12-10
CVE-2024-47593 Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform 4.3 Medium 2024-11-12
CVE-2024-41732 Improper Access Control in SAP Netweaver Application Server ABAP CWE-284 4.7 Medium 2024-08-13
CVE-2022-29610 SAP NetWeaver Application Server 跨站脚本漏洞 CWE-79 5.4 - 2022-05-11

All 14 known CVE vulnerabilities affecting SAP NetWeaver Application Server ABAP with full Chinese analysis, references, and POCs where available.