cbcvebase.

Sap Netweaver vulnerabilities

87 known vulnerabilities affecting sap/netweaver.

Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2

Vulnerabilities

Page 2 of 5
CVE-2016-3635P3HIGHCVSS 7.5v7.402016-10-13
CVE-2016-3635 [HIGH] CWE-284 CVE-2016-3635: SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.
nvd
CVE-2012-2511P4MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2511 [MEDIUM] CWE-119 CVE-2012-2511: The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2514P4MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2514 [MEDIUM] CWE-119 CVE-2012-2514: The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2612P4MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2612 [MEDIUM] CWE-119 CVE-2012-2612: The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher i The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2512P4MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2512 [MEDIUM] CWE-119 CVE-2012-2512: The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2513P4MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2513 [MEDIUM] CWE-119 CVE-2012-2513: The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in S The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2016-4014P3HIGHCVSS 8.6v7.42016-04-14
CVE-2016-4014 [HIGH] CVE-2016-4014: XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows re XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.
nvd
CVE-2018-2477P3HIGHCVSS 8.8v7.30v7.31+2 more2018-11-13
CVE-2018-2477 [HIGH] CWE-91 CVE-2018-2477: Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not suffic Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
nvd
CVE-2013-5723P3HIGHCVSS 7.5v7.302013-09-12
CVE-2013-5723 [HIGH] CWE-89 CVE-2013-5723: SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL c SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
nvd
CVE-2013-7094P3HIGHCVSS 7.5v7.302013-12-13
CVE-2013-7094 [HIGH] CWE-89 CVE-2013-7094: SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows rem SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-6869P3HIGHCVSS 7.5v7.302013-11-23
CVE-2013-6869 [HIGH] CWE-89 CVE-2013-6869: SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allo SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2024-22124P3HIGHCVSS 7.5vkernel_7.22vkernel_7.53+8 more2024-01-09
CVE-2024-22124 [HIGH] CWE-497 CVE-2024-22124: Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERN Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53, WEBDISP 7.54, could allow an attacker to access information which would otherwise be restricted causin
nvd
CVE-2018-2462P3HIGHCVSS 8.8v7.30v7.31+3 more2018-09-11
CVE-2018-2462 [HIGH] CWE-20 CVE-2018-2462: In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41 In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.
nvd
CVE-2022-28772P3HIGHCVSS 7.5v7.22extv7.49+8 more2022-04-12
CVE-2022-28772 [HIGH] CWE-121 CVE-2022-28772: By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Di By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, le
nvd
CVE-2016-4551P3HIGHCVSS 7.5v2004s2016-10-05
CVE-2016-4551 [HIGH] CWE-284 CVE-2016-4551: The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow r The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
nvd
CVE-2015-6662P3MEDIUMCVSS 6.8v7.402015-08-24
CVE-2015-6662 [MEDIUM] CVE-2015-6662: XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote attackers to read XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote attackers to read arbitrary files and possibly have other unspecified impact via crafted XML data, aka SAP Security Note 2168485.
nvd
CVE-2017-9845P3HIGHCVSS 7.5v7.402017-07-12
CVE-2017-9845 [HIGH] CWE-400 CVE-2017-9845: disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of servic disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.
nvd
CVE-2016-4015P3HIGHCVSS 7.5v7.1v7.2+2 more2016-04-14
CVE-2016-4015 [HIGH] CVE-2016-4015: The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denia The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.
nvd
CVE-2015-2815P3MEDIUMCVSS 6.5v7.0v7.402015-04-01
CVE-2015-2815 [MEDIUM] CWE-119 CVE-2015-2815: Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52. Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369.
nvd
CVE-2022-28773P4HIGHCVSS 7.5v7.22extv7.49+8 more2022-04-12
CVE-2022-28773 [HIGH] CWE-674 CVE-2022-28773: Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the a Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.
nvd
Sap Netweaver vulnerabilities | cvebase