Sap Netweaver vulnerabilities

87 known vulnerabilities affecting sap/netweaver.

Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2

Vulnerabilities

Page 4 of 5
CVE-2014-3787MEDIUMCVSS 5.0≤ 7.20v7.0+4 more2014-05-19
CVE-2014-3787 [MEDIUM] CWE-200 CVE-2014-3787: SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administra SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
nvd
CVE-2014-1963MEDIUMCVSS 5.0v7.202014-02-14
CVE-2014-1963 [MEDIUM] CVE-2014-1963: Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.
nvd
CVE-2014-1965MEDIUMCVSS 4.3v3.0v7.0+4 more2014-02-14
CVE-2014-1965 [MEDIUM] CWE-79 CVE-2014-1965: Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP E Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP.
nvd
CVE-2013-7094HIGHCVSS 7.5v7.302013-12-13
CVE-2013-7094 [HIGH] CWE-89 CVE-2013-7094: SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows rem SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-6869HIGHCVSS 7.5v7.302013-11-23
CVE-2013-6869 [HIGH] CWE-89 CVE-2013-6869: SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allo SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2013-6814MEDIUMCVSS 5.8≤ 7.02v6.42013-11-20
CVE-2013-6814 [MEDIUM] CWE-20 CVE-2013-6814: The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users t The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
nvd
CVE-2013-6815MEDIUMCVSS 5.0≤ 7.31v4.0+7 more2013-11-20
CVE-2013-6815 [MEDIUM] CWE-20 CVE-2013-6815: The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.
nvd
CVE-2013-6244MEDIUMCVSS 5.0≤ 7.31v4.0+7 more2013-10-24
CVE-2013-6244 [MEDIUM] CVE-2013-6244: The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWea The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2013-5751MEDIUMCVSS 5.0v7.0v7.01+4 more2013-09-16
CVE-2013-5751 [MEDIUM] CWE-22 CVE-2013-5751: Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary fil Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2013-5723HIGHCVSS 7.5v7.302013-09-12
CVE-2013-5723 [HIGH] CWE-89 CVE-2013-5723: SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL c SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
nvd
CVE-2013-3319MEDIUMCVSS 5.0v7.032013-08-16
CVE-2013-3319 [MEDIUM] CWE-200 CVE-2013-3319: The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attacker The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
nvd
CVE-2011-5263MEDIUMCVSS 4.3≤ 7.30v7.0+3 more2013-02-12
CVE-2011-5263 [MEDIUM] CWE-79 CVE-2011-5263: Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier a Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.
nvd
CVE-2011-5260MEDIUMCVSS 4.3v4.0v6.4+1 more2013-02-12
CVE-2011-5260 [MEDIUM] CWE-79 CVE-2011-5260: Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attac Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via the page parameter.
nvd
CVE-2012-2611CRITICALCVSS 9.3PoCv7.02012-05-15
CVE-2012-2611 [CRITICAL] CWE-20 CVE-2012-2611: The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.1 The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.
nvd
CVE-2012-2514MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2514 [MEDIUM] CWE-119 CVE-2012-2514: The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2511MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2511 [MEDIUM] CWE-119 CVE-2012-2511: The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2612MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2612 [MEDIUM] CWE-119 CVE-2012-2612: The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher i The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2512MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2512 [MEDIUM] CWE-119 CVE-2012-2512: The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-2513MEDIUMCVSS 5.0PoCv7.02012-05-15
CVE-2012-2513 [MEDIUM] CWE-119 CVE-2012-2513: The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in S The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
nvd
CVE-2012-1292MEDIUMCVSS 5.0v7.02012-02-23
CVE-2012-1292 [MEDIUM] CVE-2012-1292: Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attacker Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the MessagingSystem Performance Data via unspecified vectors.
nvd