CVE-2023-0014: SAP NetWeaver Application Server Abap

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

Affected products

  • SAP NetWeaver Application Server Abap: version 700 only; version 701 only; version 702 only; version 710 only; version 711 only; version 730 only; …
  • SAP NetWeaver Application Server Abap Kernel: version 7.22 only; version 7.53 only; version 7.77 only; version 7.81 only; version 7.85 only; version 7.89 only
  • SAP NetWeaver Application Server Abap KRNL64NUC: version 7.22 only; version 7.22ext only
  • SAP NetWeaver Application Server Abap KRNL64UC: version 7.22 only; version 7.22ext only; version 7.53 only

Published 2023-01-10. Last modified 2026-06-17.