Netweaver Application Server Abap
Vendor:
First CVE: Feb 15, 2019 · Active for 7 years
86
Total CVEs
More Total CVEs than 99% of tracked products
12.3
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Netweaver Application Server Abap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 15, 2019
7 years ago
Most Recent CVE
May 14, 2026
75 days ago
CVE Severity & Scoring
Netweaver Application Server Abap86 CVEs
63%
21%
13%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.3%)
Network84 (97.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low86 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None63 (73.3%)
Unknown0 (0.0%)
Required23 (26.7%)
Privileges Required
Low39 (45.3%)
High11 (12.8%)
None36 (41.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (86 CVEs).
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22536CRITICAL SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and | Feb 9, 2022 | 10.0 | 98 | YES | YES |
CVE-2026-0488CRITICAL An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, wh | Feb 10, 2026 | 9.9 | 35 | NO | NO |
CVE-2023-0014CRITICAL SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85 | Jan 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-44231CRITICAL Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | Dec 14, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-27610CRITICAL SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user | Jun 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-0506HIGH Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FO | Jan 13, 2026 | 8.1 | 29 | NO | NO |
CVE-2023-27501CRITICAL SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation o | Mar 14, 2023 | 9.6 | 29 | NO | NO |
CVE-2023-27269CRITICAL SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrat | Mar 14, 2023 | 9.6 | 29 | NO | NO |
CVE-2021-40499CRITICAL Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject co | Oct 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2026-40135MEDIUM An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to | May 12, 2026 | 6.5 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (86 CVEs).
CISA KEV
1 CVE
1.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.2% of CVEs· 96th percentile
ExploitDB
1 CVE
1.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (86 CVEs).
Media Mentions
Signals from CVEs in this product scope (86 CVEs).
Top CNAs Publishing CVEs For Netweaver Application Server Abap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| st-pi_2008_1_700 | 1 | 6.5 | 0.4% | 0 | 0 |
| sap_ui_754 | 1 | 5.4 | 0.3% | 0 | 0 |
| sap_basis_912 | 2 | 4.8 | 0.3% | 0 | 0 |
| sap_basis_758 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_757 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_756 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_755 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_754 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_753 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_752 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_751 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_750 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_740 | 1 | 4.3 | 0.3% | 0 | 0 |
| sap_basis_731 | 2 | 4.8 | 0.3% | 0 | 0 |
| sap_basis_702 | 2 | 4.8 | 0.3% | 0 | 0 |
| sap_basis_701 | 2 | 4.8 | 0.3% | 0 | 0 |
| sap_basis_700 | 2 | 4.8 | 0.3% | 0 | 0 |
| krnl64uc_8.04 | 3 | 6.9 | 33.2% | 1 | 1 |
| krnl64uc_7.73 | 1 | 5.3 | 0.8% | 0 | 0 |
| krnl64uc_7.53 | 5 | 6.7 | 20.0% | 1 | 1 |