CVE-2023-28763: SAP NetWeaver Application Server Abap

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

Affected products

  • SAP NetWeaver Application Server Abap: version 740 only; version 750 only; version 751 only; version 752 only; version 753 only; version 754 only; …

Published 2023-04-11. Last modified 2026-06-17.