Abap Platform
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Abap Platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Abap Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High2
- Medium7
- Low2
Latest CVEs
The 13 most recently published vulnerabilities affecting Abap Platform.
- CVE-2025-42949Missing Authorization check in ABAP Platform4.9
- CVE-2024-27900Missing Authorization check in SAP ABAP Platform4.3
- CVE-2024-22131Code Injection vulnerability in SAP ABA (Application Basis)9.1
- CVE-2023-29110Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)3.7
- CVE-2023-29109Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard)4.4
- CVE-2023-25615SQL Injection vulnerability in SAP ABAP Platform6.8
- CVE-2021-44231Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.9.8
- CVE-2020-6318A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Co...7.2
- CVE-2020-6310Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP...4.3
- CVE-2020-6299SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Info...4.3
- CVE-2020-6296SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, lead...8.8
- CVE-2020-6280SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information ...2.7
- CVE-2020-6181Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attack...5.8
Product grouping is registry-driven, with AI assist and human review. How it works