CVE-2023-49581: SAP NetWeaver Application Server Abap
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.
Affected products
- SAP NetWeaver Application Server Abap: version 700 only; version 731 only; version 740 only; version 750 only
Published 2023-12-12. Last modified 2026-06-17.