Vulnerabilities > SAP > Netweaver Application Server Abap > 7.54

DATE CVE VULNERABILITY TITLE RISK
2023-04-11 CVE-2023-27499 Cross-site Scripting vulnerability in SAP Netweaver and Netweaver Application Server Abap
SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2022-09-13 CVE-2022-35294 Unspecified vulnerability in SAP Netweaver Application Server Abap
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack.
network
low complexity
sap
5.4
2022-09-13 CVE-2022-39799 Unspecified vulnerability in SAP Netweaver Application Server Abap
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack.
network
low complexity
sap
6.1