← Vulnerability feed

Vulnerability record · CVE-2023-25615 · published 14 March 2023

CVE-2023-25615: Sap abap platform sql injection vulnerability

Sap · Abap Platform

Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database queries over the network and gain access to the unintended data. This may lead to a high impact on the confidentiality and no impact on the availability and integrity of the application.

4.9 CVSS 3.1 Medium EPSS 0.55% · top 56.5% CWE-89 · SQL injection
4.9CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database queries over the network and gain access to the unintended data. This may lead to a high impact on the confidentiality and no impact on the availability and integrity of the application.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25615 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44231Sap abap platform code injection vulnerabilityInternally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…EPSS 1.3%8.8CVE-2020-6296Sap abap platform vulnerabilitySAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…EPSS 1.3%7.2CVE-2024-22131Sap abap platform code injection vulnerabilityIn SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…EPSS 1.1%7.2CVE-2020-6318Sap abap platform code injection vulnerabilityA Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…EPSS 5.8%5.8CVE-2020-6181Sap abap platform vulnerabilityUnder some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS ver…EPSS 0.78%5.4CVE-2023-29110Sap abap platform cross-site scripting vulnerabilityThe SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, applicati…EPSS 0.32%5.3CVE-2024-27900Sap abap platform missing authorization vulnerabilityDue to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…EPSS 0.39%4.6CVE-2023-29109Sap abap platform csv injection vulnerabilityThe SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, appl…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2023-25615), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.