cbcvebase.

Sap Netweaver vulnerabilities

87 known vulnerabilities affecting sap/netweaver.

Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2

Vulnerabilities

Page 4 of 5
CVE-2021-38183P4MEDIUMCVSS 6.1v700v701+2 more2021-10-12
CVE-2021-38183 [MEDIUM] CWE-79 CVE-2021-38183: SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, al SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
nvd
CVE-2020-6185P4MEDIUMCVSS 5.4v7.402020-02-12
CVE-2020-6185 [MEDIUM] CWE-79 CVE-2020-6185: Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4 Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
nvd
CVE-2023-33984P4MEDIUMCVSS 5.4v7.502023-06-13
CVE-2023-33984 [MEDIUM] CWE-79 CVE-2023-33984: SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant message. Under certain circumstances, this could lead to Cross-Site Scripting vulnerability.
nvd
CVE-2016-1911P4MEDIUMCVSS 6.1v7.402016-01-15
CVE-2016-1911 [MEDIUM] CWE-79 CVE-2016-1911: Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to i Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest servlet in the Process Monitoring Infrastructure (PMI), aka SAP Security Notes 2206793 and 2234918.
nvd
CVE-2020-6184P4MEDIUMCVSS 6.1v7.402020-02-12
CVE-2020-6184 [MEDIUM] CWE-79 CVE-2020-6184: Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/ Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2015-2817P4MEDIUMCVSS 5.0v7.402015-04-01
CVE-2015-2817 [MEDIUM] CWE-200 CVE-2015-2817: The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive informa The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.
nvd
CVE-2014-8592P4MEDIUMCVSS 5.0v7.02v7.302014-11-04
CVE-2014-8592 [MEDIUM] CVE-2014-8592: Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote at Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via a crafted request.
nvd
CVE-2025-42968P4MEDIUMCVSS 4.3v700v701+16 more2025-07-08
CVE-2025-42968 [MEDIUM] CWE-862 CVE-2025-42968: SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function mo SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the
nvd
CVE-2013-6814P4MEDIUMCVSS 5.8≤ 7.02v6.42013-11-20
CVE-2013-6814 [MEDIUM] CWE-20 CVE-2013-6814: The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users t The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
nvd
CVE-2014-8591P4MEDIUMCVSS 5.0v7.02v7.302014-11-04
CVE-2014-8591 [MEDIUM] CVE-2014-8591: Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via unknown vectors.
nvd
CVE-2013-6815P4MEDIUMCVSS 5.0≤ 7.31v4.0+7 more2013-11-20
CVE-2013-6815 [MEDIUM] CWE-20 CVE-2013-6815: The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.
nvd
CVE-2012-1291P4MEDIUMCVSS 5.0v7.02012-02-23
CVE-2012-1291 [MEDIUM] CVE-2012-1291: Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7 Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service.
nvd
CVE-2012-1292P4MEDIUMCVSS 5.0v7.02012-02-23
CVE-2012-1292 [MEDIUM] CVE-2012-1292: Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attacker Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the MessagingSystem Performance Data via unspecified vectors.
nvd
CVE-2014-1963P4MEDIUMCVSS 5.0v7.202014-02-14
CVE-2014-1963 [MEDIUM] CVE-2014-1963: Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.
nvd
CVE-2012-1289P4MEDIUMCVSS 4.0v7.02012-02-23
CVE-2012-1289 [MEDIUM] CWE-22 CVE-2012-1289: Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users t Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admin/log.jsp or (4) ipc/admin/log_view.jsp in the Application Administrat
nvd
CVE-2018-2434P4MEDIUMCVSS 4.3v7.02018-07-10
CVE-2018-2434 [MEDIUM] CWE-345 CVE-2018-2434: A content spoofing vulnerability in the following components allows to render html pages containing A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.5
nvd
CVE-2014-1965P4MEDIUMCVSS 4.3v3.0v7.0+4 more2014-02-14
CVE-2014-1965 [MEDIUM] CWE-79 CVE-2014-1965: Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP E Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP.
nvd
CVE-2009-2932P4MEDIUMCVSS 4.3v7.02009-08-21
CVE-2009-2932 [MEDIUM] CWE-79 CVE-2009-2932: Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver A Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.
nvd
CVE-2011-5263P4MEDIUMCVSS 4.3≤ 7.30v7.0+3 more2013-02-12
CVE-2011-5263 [MEDIUM] CWE-79 CVE-2011-5263: Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier a Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.
nvd
CVE-2010-2904P4MEDIUMCVSS 4.3v6.4v7.02010-07-28
CVE-2010-2904 [MEDIUM] CWE-79 CVE-2010-2904: Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) componen Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.
nvd
Sap Netweaver vulnerabilities | cvebase