3218177 |
BC-FES-WGU |
[CVE-2022-35294] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP |
5.4 |
Medium |
2022-09 |
2022/09/13 |
Program error |
ABAP |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.54
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.89
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
|
3123396 |
BC-CST-IC |
[CVE-2022-22536] Request smuggling and request concatenation in SAP NetWeaver, SAP Content Server and SAP Web Dispatcher |
10.0 |
Hot News |
2022-02 |
2022/02/08 |
Program error |
Kernel |
CONTSERV 7.53
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
WEBDISP 7.22_EXT
WEBDISP 7.49
WEBDISP 7.53
WEBDISP 7.77
WEBDISP 7.81
WEBDISP 7.85
WEBDISP 7.86
WEBDISP 7.87
|
3080567 |
BC-CST-WDP |
[CVE-2021-38162] HTTP Request Smuggling in SAP Web Dispatcher |
8.9 |
High |
2021-09 |
2021/09/14 |
Program error |
Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.83
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
WEBDISP 7.53
WEBDISP 7.77
WEBDISP 7.81
|
3111293 |
BC-CST-WDP |
[CVE-2022-28773] Denial of service (DOS) in SAP Web Dispatcher and SAP Netweaver (Internet Communication Manager) |
4.9 |
Medium |
2022-04 |
2022/04/12 |
Program error |
Kernel |
HDB 2.00
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
WEBDISP 7.53
WEBDISP 7.77
WEBDISP 7.81
WEBDISP 7.85
WEBDISP 7.86
|
3123427 |
BC-CST-IC |
[CVE-2022-22532] HTTP Request Smuggling in SAP NetWeaver Application Server Java |
8.1 |
High |
2022-02 |
2022/02/08 |
Program error |
Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
|
3145046 |
BC-CST-WDP |
[CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM) |
8.3 |
High |
2022-05 |
2022/05/10 |
Program error |
Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
WEBDISP 7.22_EXT
WEBDISP 7.49
WEBDISP 7.53
WEBDISP 7.77
WEBDISP 7.81
WEBDISP 7.85
|
3116223 |
BC-CST |
[CVE-2022-22543] Denial of service (DOS) in SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) |
3.7 |
Low |
2022-02 |
2022/02/08 |
Program error |
Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
|
3155571 |
BC-DB-SYB |
[CVE-2022-31594] Privilege escalation vulnerability in SAP Adaptive Server Enterprise (ASE) |
3.2 |
Low |
2022-06 |
2022/06/14 |
Program error |
SAP Adaptive Server Enterprise (ASE) |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EX2
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
|
3000663 |
BC-CST-WDP |
[CVE-2021-33683] HTTP Request Smuggling in SAP Web Dispatcher and Internet Communication Manager |
5.4 |
Medium |
2021-07 |
2021/07/13 |
Program error |
Kernel |
HDB 2.00
KERNEL 7.21-7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.73
KERNEL 7.77
KERNEL 7.81
KERNEL 7.82
KERNEL 7.83
KRNL32NUC 7.21
KRNL32NUC 7.21EXT
KRNL32UC 7.21
KRNL32UC 7.21EXT
KRNL64NUC 7.21
KRNL64NUC 7.21EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.21
KRNL64UC 7.21EXT
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.73
SAP_EXTENDED_APP_SERVICES 1
WEBDISP 7.53
WEBDISP 7.73
WEBDISP 7.77
WEBDISP 7.81
WEBDISP 7.82
WEBDISP 7.83
XS_ADVANCED_RUNTIME 1.00
|
3194674 |
BC-CST-STS |
[CVE-2022-29612] Server-Side Request Forgery in SAP NetWeaver, ABAP Platform and SAP Host Agent |
5.0 |
Medium |
2022-06 |
2022/06/14 |
Program error |
ABAP SAP Host Agent |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 7.88
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
SAPHOSTAGENT 7.22
|
3158619 |
BC-CST-STS |
[CVE-2022-29614] Privilege Escalation in SAP startservice of SAP NetWeaver AS ABAP, AS Java, ABAP Platform and HANA Database |
4.9 |
Medium |
2022-06 |
2022/06/14 |
Program error |
ABAP Java HANA platform |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 7.88
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
SAPHOSTAGENT 7.22
|
3158375 |
BC-CST-NI |
[CVE-2022-27668] Improper Access Control of SAProuter for SAP NetWeaver and ABAP Platform |
8.6 |
High |
2022-06 |
2022/06/14 |
Program error |
SAProuter |
KERNEL 7.49
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 7.88
KRNL64NUC 7.49
KRNL64UC 7.49
SAP_ROUTER 7.22
SAP_ROUTER 7.53
|
2736825 |
BC-ABA-XML |
[CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server |
6.5 |
Medium |
2020-02 |
2019/03/12 |
Consulting |
ABAP |
KRNL32NUC 7.21
KRNL32NUC 7.21EXT
KRNL32NUC 7.22
KRNL32NUC 7.22EXT
KRNL32UC 7.21
KRNL32UC 7.21EXT
KRNL32UC 7.22
KRNL32UC 7.22EXT
KRNL64NUC 7.21
KRNL64NUC 7.21EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.21
KRNL64UC 7.21EXT
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KERNEL 7.21-7.22
KERNEL 7.45
KERNEL 7.49
KERNEL 7.53
|
2870067 |
BC-ABA-XML |
Update 1 to Security Note 2736825 - [CVE-2019-0271] Denial of Service via XML External Entity (XXE) vulnerability in ABAP Server |
6.5 |
Medium |
2020-02 |
2020/02/11 |
Program error |
ABAP |
KRNL64NUC 7.49
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.73
KERNEL 7.49
KERNEL 7.53
KERNEL 7.73
KERNEL 7.77
KERNEL 7.78
KERNEL 7.79
|
3145702 |
BC-CST-MS |
[CVE-2022-29616] Memory Corruption vulnerability in SAP Host Agent, SAP NetWeaver and ABAP Platform |
5.3 |
Medium |
2022-05 |
2022/05/10 |
Program error |
SAP Host Agent Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.86
KERNEL 7.87
KERNEL 7.88
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
SAPHOSTAGENT 7.22
|
3057378 |
BC-CST-WDP |
Missing Authentication check in SAP Web Dispatcher |
8.8 |
High |
2021-08 |
2021/08/10 |
Program error |
Kernel |
HDB 2.00
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.83
KERNEL 7.84
KERNEL 8.04
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
SAP_EXTENDED_APP_SERVICES 1
WEBDISP 7.22_EXT
WEBDISP 7.49
WEBDISP 7.53
WEBDISP 7.77
WEBDISP 7.81
XS_ADVANCED_RUNTIME 1.00
|
3032624 |
BC-MID-RFC |
[CVE-2021-33684] Memory Corruption in SAP NetWeaver AS ABAP and ABAP Platform |
5.3 |
Medium |
2021-07 |
2021/07/13 |
Program error |
Kernel |
KERNEL 7.21-7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.84
KERNEL 8.04
KRNL32NUC 7.21
KRNL32NUC 7.21EXT
KRNL32NUC 7.22
KRNL32NUC 7.22EXT
KRNL32UC 7.21
KRNL32UC 7.21EXT
KRNL32UC 7.22
KRNL32UC 7.22EXT
KRNL64NUC 7.21
KRNL64NUC 7.21EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.21
KRNL64UC 7.21EXT
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 8.04
|
2973428 |
BC-FES-ITS |
Reverse Tabnabbing vulnerability within SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML) |
4.7 |
Medium |
2021-02 |
2021/02/09 |
Program error |
Kernel |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.73
KERNEL 7.77
KERNEL 7.81
KRNL32NUC 7.22
KRNL32NUC 7.22EXT
KRNL32UC 7.22
KRNL32UC 7.22EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.73
|
3233899 |
BC-CST-WDP |
[CVE-2023-33987] Request smuggling and request concatenation vulnerability in SAP Web Dispatcher |
8.6 |
High |
2023-07 |
2023/07/11 |
Program error |
Kernel |
HDB 2.00
KERNEL 7.49
KERNEL 7.53
KERNEL 7.54
KERNEL 7.77
KERNEL 7.81
KERNEL 7.85
KERNEL 7.88
KERNEL 7.89
KERNEL 7.90
KRNL64NUC 7.49
KRNL64UC 7.49
KRNL64UC 7.53
SAP_EXTENDED_APP_SERVICES 1
WEBDISP 7.49
WEBDISP 7.53
WEBDISP 7.54
WEBDISP 7.77
WEBDISP 7.81
WEBDISP 7.85
WEBDISP 7.88
WEBDISP 7.89
WEBDISP 7.90
XS_ADVANCED_RUNTIME 1.00
|
3030604 |
BC-CST-IC |
[CVE-2021-33663] Plaintext Injection in SAP NetWeaver AS for ABAP |
5.8 |
Medium |
2021-06 |
2021/06/08 |
Program error |
ABAP |
KERNEL 7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.73
KERNEL 7.77
KERNEL 7.81
KERNEL 7.82
KERNEL 7.83
KERNEL 7.84
KERNEL 8.04
KRNL32NUC 7.22
KRNL32NUC 7.22EXT
KRNL32UC 7.22
KRNL32UC 7.22EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.73
KRNL64UC 8.04
|
3028370 |
BC-FES-WGU |
[CVE-2021-33665] Cross-Site Scripting (XSS) vulnerability within SAP NetWeaver AS ABAP (Applications based on SAP GUI for HTML) |
5.4 |
Medium |
2021-06 |
2021/06/08 |
Program error |
ABAP |
KERNEL 7.49
KERNEL 7.53
KERNEL 7.77
KERNEL 7.81
KERNEL 7.84
KRNL64NUC 7.49
KRNL64UC 7.49
KRNL64UC 7.53
|
3007182 |
BC-MID-RFC |
[CVE-2021-27610] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform |
9.0 |
Hot News |
2021-07 |
2021/06/08 |
Program error |
ABAP |
KERNEL 7.21-7.22
KERNEL 7.49
KERNEL 7.53
KERNEL 7.73
KERNEL 7.77
KERNEL 7.81
KERNEL 7.84
KERNEL 8.04
KRNL32NUC 7.21
KRNL32NUC 7.21EXT
KRNL32NUC 7.22
KRNL32NUC 7.22EXT
KRNL32UC 7.21
KRNL32UC 7.21EXT
KRNL32UC 7.22
KRNL32UC 7.22EXT
KRNL64NUC 7.21
KRNL64NUC 7.21EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.21
KRNL64UC 7.21EXT
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.73
KRNL64UC 8.04
SAP_BASIS 700-702
SAP_BASIS 710-711
SAP_BASIS 730
SAP_BASIS 731
SAP_BASIS 740
SAP_BASIS 750-755
SAP_BASIS 783
SAP_BASIS 804
|
2848498 |
BC-CST-IC |
[CVE-2020-6304] Denial of service (DOS) in SAP NetWeaver Internet Communication Manager |
5.9 |
Medium |
2020-01 |
2020/01/14 |
Program error |
Kernel |
KRNL32NUC 7.21
KRNL32NUC 7.21EXT
KRNL32UC 7.21
KRNL32UC 7.21EXT
KRNL64NUC 7.21
KRNL64NUC 7.21EXT
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64UC 7.21
KRNL64UC 7.21EXT
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KERNEL 7.21-7.22
KERNEL 7.49
KERNEL 7.53
|
3051787 |
BC-IAM-SSO-CCL |
[CVE-2021-38177] Null Pointer Dereference vulnerability in SAP CommonCryptoLib |
7.5 |
High |
2021-09 |
2021/09/14 |
Program error |
ABAP Java HANA platform |
HDB 2.00
KRNL64NUC 7.22
KRNL64NUC 7.22EXT
KRNL64NUC 7.49
KRNL64NUC 7.53
KRNL64NUC 7.22EX2
KRNL64NUC 7.77
KRNL64UC 8.04
KRNL64UC 7.22
KRNL64UC 7.22EXT
KRNL64UC 7.49
KRNL64UC 7.53
KRNL64UC 7.77
KRNL64UC 7.81
KRNL64UC 7.85
KRNL64UC 7.83
KRNL64UC 7.84
WEBDISP 7.49
WEBDISP 7.53
WEBDISP 7.77
|