SAP NetWeaver Application Server ABAP 804

CPE Details

SAP NetWeaver Application Server ABAP 804
804
2022-10-05
11h56 +00:00
2022-10-06
13h20 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sap:netweaver_application_server_abap:804:*:*:*:*:*:*:*

Informations

Vendor

sap

Product

netweaver_application_server_abap

Version

804

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-41212 2022-11-07 23h00 +00:00 Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.
4.9
Medium
CVE-2022-41214 2022-11-07 23h00 +00:00 Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of the application.
8.7
High
CVE-2021-44231 2021-12-14 14h44 +00:00 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
9.8
Critical
CVE-2021-33677 2021-07-14 09h03 +00:00 SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure.
7.5
High
CVE-2021-27610 2021-06-16 12h45 +00:00 SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.
9.8
Critical
CVE-2020-6240 2020-05-12 15h46 +00:00 SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service
7.5
High