cbcvebase.

Sap Netweaver vulnerabilities

87 known vulnerabilities affecting sap/netweaver.

Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2

Vulnerabilities

Page 1 of 5
CVE-2025-31324P1CRITICALCVSS 9.8KEVPoCRansomwarev7.502025-04-24
CVE-2025-31324 [CRITICAL] CWE-434 CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowi SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
nvd
CVE-2021-38163P1HIGHCVSS 8.8KEVPoCv7.30v7.31+2 more2021-09-14
CVE-2021-38163 [HIGH] CWE-22 CVE-2021-38163: SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an at SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to re
nvd
CVE-2025-42999P1CRITICALCVSS 9.1KEVRansomwarev7.52025-05-13
CVE-2025-42999 [CRITICAL] CWE-502 CVE-2025-42999: SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untr SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
nvd
CVE-2016-2389P1HIGHCVSS 7.5ExploitedPoCv7.402016-02-16
CVE-2016-2389 [HIGH] CWE-22 CVE-2016-2389: Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration a Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.
nvd
CVE-2017-9844P2HIGHCVSS 7.5Exploitedv7400.12.21.303082017-07-12
CVE-2017-9844 [HIGH] CWE-502 CVE-2017-9844: SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly exe SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users
nvd
CVE-2013-1592P2CRITICALCVSS 9.8PoCv7.01v7.02+2 more2020-01-23
CVE-2013-1592 [CRITICAL] CWE-120 CVE-2013-1592: A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() functio A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.
nvd
CVE-2012-2611P2CRITICALCVSS 9.3PoCv7.02012-05-15
CVE-2012-2611 [CRITICAL] CWE-20 CVE-2012-2611: The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.1 The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.
nvd
CVE-2015-7241P2CRITICALCVSS 9.8PoC≤ 7.02017-09-06
CVE-2015-7241 [CRITICAL] CWE-611 CVE-2015-7241: XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
nvd
CVE-2011-1517P3CRITICALCVSS 9.8PoCv7.02020-02-05
CVE-2011-1517 [CRITICAL] CVE-2011-1517: SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagT SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.
nvd
CVE-2013-1593P3HIGHCVSS 7.5PoCv7.01v7.02+2 more2020-01-23
CVE-2013-1593 [HIGH] CWE-129 CVE-2013-1593: A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN.
nvd
CVE-2016-1910P3MEDIUMCVSS 5.3PoCv7.402016-01-15
CVE-2016-1910 [MEDIUM] CWE-200 CVE-2016-1910: The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data v The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
nvd
CVE-2013-3319P3MEDIUMCVSS 5.0PoCv7.032013-08-16
CVE-2013-3319 [MEDIUM] CWE-200 CVE-2013-3319: The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attacker The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
nvd
CVE-2019-0351P3HIGHCVSS 8.8v7.10v7.20+4 more2019-08-14
CVE-2019-0351 [HIGH] CVE-2019-0351: A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), v A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory which
nvd
CVE-2023-36922P3HIGHCVSS 8.8v600v602+13 more2023-07-11
CVE-2023-36922 [HIGH] CWE-78 CVE-2023-36922: Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
nvd
CVE-2016-10311P3CRITICALCVSS 9.8v7.0v7.3+2 more2017-04-10
CVE-2016-10311 [CRITICAL] CWE-119 CVE-2016-10311: Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a deni Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.
nvd
CVE-2020-6203P3CRITICALCVSS 9.1v7.10v7.11+5 more2020-03-10
CVE-2020-6203 [CRITICAL] CWE-22 CVE-2020-6203: SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; a SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
nvd
CVE-2023-29186P3MEDIUMCVSS 6.5v707v737+2 more2023-04-11
CVE-2023-29186 [MEDIUM] CWE-22 CVE-2023-29186: In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.
nvd
CVE-2014-0995P4MEDIUMCVSS 5.0PoC≤ 7.01v7.202014-11-06
CVE-2014-0995 [MEDIUM] CWE-20 CVE-2014-0995: The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to ca The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern.
nvd
CVE-2016-7435P3CRITICALCVSS 9.1v7.402016-10-05
CVE-2016-7435 [CRITICAL] CWE-264 CVE-2016-7435: The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG fun The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.
nvd
CVE-2021-21481P3HIGHCVSS 8.8v7.10v7.11+5 more2021-03-09
CVE-2021-21481 [HIGH] CWE-863 CVE-2021-21481: The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7. The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, a
nvd
Sap Netweaver vulnerabilities | cvebase