Sap Netweaver Application Server Abap and Abap Platform
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Sap Netweaver Application Server Abap and Abap Platform, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Sap Netweaver Application Server Abap and Abap Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High2
- Medium9
Latest CVEs
The 13 most recently published vulnerabilities affecting Sap Netweaver Application Server Abap and Abap Platform.
- CVE-2026-58236OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform5.5
- CVE-2026-0509Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform9.6
- CVE-2026-0506Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform8.1
- CVE-2025-42969Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform6.1
- CVE-2025-31329Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform6.2
- CVE-2024-41734Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform4.3
- CVE-2024-33006File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform9.6
- CVE-2024-32733Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform6.1
- CVE-2023-49581SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform4.1
- CVE-2023-41366Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform5.3
- CVE-2022-41214Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which i...8.7
- CVE-2022-41212Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is ...4.9
- CVE-2022-22545A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - version...4.9
Product grouping is registry-driven, with AI assist and human review. How it works