Known vulnerabilities in SAP NetWeaver AS ABAP 914
Vendor:
SAP
Software:
SAP NetWeaver AS ABAP
Version:
914
Software CPE:
cpe:2.3:a:sap:sap_netweaver_as_abap:*:*:*:*:*:*:*:*
Website:
https://www.sap.com/
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117345 - Memory corruption CVE-2025-42902 |
CWE-119 | Medium | - | 17.10.2025 |
SB2025101738 |
||
| #VU110686 - Missing Authorization CVE-2025-42989 |
CWE-862 | Medium | - | 10.06.2025 |
SB2025061012 |
||
| #VU105495 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-25242 |
CWE-79 | Low | - | 11.03.2025 |
SB2025031119 |
||
| #VU105494 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-26659 |
CWE-79 | Low | - | 11.03.2025 |
SB2025031119 |
||
| #VU105493 - Missing Authorization CVE-2025-26661 |
CWE-862 | Medium | - | 11.03.2025 |
SB2025031119 |
||
| #VU102665 - Exposure of sensitive information to an unauthorized actor CVE-2025-0059 |
CWE-200 | Low | - | 14.01.2025 |
SB2025011455 |
||
| #VU102586 - Exposure of sensitive information to an unauthorized actor CVE-2025-0066 |
CWE-200 | Medium | - | 14.01.2025 |
SB2025011427 |
||
| #VU102585 - Improper Authentication CVE-2025-0070 |
CWE-287 | Medium | - | 14.01.2025 |
SB2025011427 |