cbcvebase.

Sap Netweaver vulnerabilities

87 known vulnerabilities affecting sap/netweaver.

Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2

Vulnerabilities

Page 3 of 5
CVE-2014-6252P4MEDIUMCVSS 6.5v7.0v7.202014-09-05
CVE-2014-6252 [MEDIUM] CWE-119 CVE-2014-6252: Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP Net Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated users to cause a denial of service or execute arbitrary code via unspecified vectors.
nvd
CVE-2020-6285P4MEDIUMCVSS 6.5v7.10v7.11+5 more2020-07-14
CVE-2020-6285 [MEDIUM] CVE-2020-6285: SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
nvd
CVE-2022-28217P4MEDIUMCVSS 6.5v7.20v7.30+3 more2022-06-13
CVE-2022-28217 [MEDIUM] CWE-918 CVE-2022-28217: Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document acc Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
nvd
CVE-2019-0248P4MEDIUMCVSS 5.9v7.5v7.51+2 more2019-01-08
CVE-2019-0248 [MEDIUM] CVE-2019-0248: Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2022-22534P4MEDIUMCVSS 6.1v700v701+10 more2022-02-09
CVE-2022-22534 [MEDIUM] CWE-79 CVE-2022-22534: Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inje Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
nvd
CVE-2023-41367P4MEDIUMCVSS 5.3v7.502023-09-12
CVE-2023-41367 [MEDIUM] CWE-306 CVE-2023-41367: Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability imp
nvd
CVE-2013-5751P4MEDIUMCVSS 5.0v7.0v7.01+4 more2013-09-16
CVE-2013-5751 [MEDIUM] CWE-22 CVE-2013-5751: Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary fil Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2013-6244P4MEDIUMCVSS 5.0≤ 7.31v4.0+7 more2013-10-24
CVE-2013-6244 [MEDIUM] CVE-2013-6244: The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWea The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2024-27898P4MEDIUMCVSS 5.3v7.52024-04-09
CVE-2024-27898 [MEDIUM] CWE-918 CVE-2024-27898: SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafte SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on con
nvd
CVE-2020-6181P4MEDIUMCVSS 5.8v7.02v7.30+2 more2020-02-12
CVE-2020-6181 [MEDIUM] CVE-2020-6181: Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 7 Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
nvd
CVE-2023-0021P4MEDIUMCVSS 6.1v700v701+4 more2023-03-14
CVE-2023-0021 [MEDIUM] CWE-79 CVE-2023-0021: Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, a Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially
nvd
CVE-2014-3787P4MEDIUMCVSS 5.0≤ 7.20v7.0+4 more2014-05-19
CVE-2014-3787 [MEDIUM] CWE-200 CVE-2014-3787: SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administra SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
nvd
CVE-2023-26461P4MEDIUMCVSS 4.9v7.502023-03-14
CVE-2023-26461 [MEDIUM] CWE-611 CVE-2023-26461: SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with s SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.
nvd
CVE-2018-2464P4MEDIUMCVSS 6.1v7.20v7.30+3 more2018-09-11
CVE-2018-2464 [MEDIUM] CWE-79 CVE-2018-2464: SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-control SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2024-25644P4MEDIUMCVSS 5.3v7.502024-03-12
CVE-2024-25644 [MEDIUM] CWE-732 CVE-2024-25644: Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
nvd
CVE-2023-33985P4MEDIUMCVSS 6.1v7.502023-06-13
CVE-2023-33985 [MEDIUM] CWE-79 CVE-2023-33985: SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integri
nvd
CVE-2023-27499P4MEDIUMCVSS 6.1v7.22ext2023-04-11
CVE-2023-27499 [MEDIUM] CWE-79 CVE-2023-27499: SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7 SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the atta
nvd
CVE-2016-2387P4MEDIUMCVSS 6.1v7.402016-02-16
CVE-2016-2387 [MEDIUM] CWE-79 CVE-2016-2387: Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or (2) interface parameter to ProxyServer/register, aka SAP Security Note 2220571.
nvd
CVE-2018-2470P4MEDIUMCVSS 6.1≥ 7.0, ≤ 7.02≥ 7.50, ≤ 7.53+3 more2018-10-09
CVE-2018-2470 [MEDIUM] CWE-79 CVE-2018-2470: In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7. In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2018-2476P4MEDIUMCVSS 6.1v7.30v7.31+1 more2018-11-13
CVE-2018-2476 [MEDIUM] CWE-601 CVE-2018-2476: Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
nvd
Sap Netweaver vulnerabilities | cvebase