Known vulnerabilities in SAP NetWeaver AS ABAP 816
Vendor:
SAP
Software:
SAP NetWeaver AS ABAP
Version:
816
Software CPE:
cpe:2.3:a:sap:sap_netweaver_as_abap:*:*:*:*:*:*:*:*
Website:
https://www.sap.com/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
5.3
Vulnerabilities by Severity
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125963 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2026-34257 |
CWE-601 | Low | - | 14.04.2026 |
SB2026041494 |
||
| #VU125970 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-27680 |
CWE-79 | Low | - | 14.04.2026 |
SB2026041494 |
||
| #VU123670 - Missing Authorization CVE-2026-24310 |
CWE-862 | Low | - | 10.03.2026 |
SB2026031033 |
||
| #VU123669 - Missing Authorization CVE-2026-27688 |
CWE-862 | Low | - | 10.03.2026 |
SB2026031033 |
||
| #VU123667 - Missing Authorization CVE-2026-24309 |
CWE-862 | Medium | - | 10.03.2026 |
SB2026031033 |
||
| #VU123666 - Server-Side Request Forgery (SSRF) CVE-2026-24316 |
CWE-918 | Medium | - | 10.03.2026 |
SB2026031033 |
||
| #VU117343 - Improper Control of Generation of Code ('Code Injection') CVE-2025-42901 |
CWE-94 | Medium | - | 17.10.2025 |
SB2025101738 |