Sap Netweaver vulnerabilities
87 known vulnerabilities affecting sap/netweaver.
Total CVEs
87
CISA KEV
3
actively exploited
Public exploits
16
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH20MEDIUM56LOW2
Vulnerabilities
Page 5 of 5
CVE-2011-5260P4MEDIUMCVSS 4.3v4.0v6.4+1 more2013-02-12
CVE-2011-5260 [MEDIUM] CWE-79 CVE-2011-5260: Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attac
Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via the page parameter.
nvd
CVE-2012-1290P4MEDIUMCVSS 4.3v7.02012-02-23
CVE-2012-1290 [MEDIUM] CWE-79 CVE-2012-1290: Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b
Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.
nvd
CVE-2026-23685P4MEDIUMCVSS 4.4v7.502026-02-10
CVE-2026-23685 [MEDIUM] CWE-502 CVE-2026-23685: Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successfu
nvd
CVE-2008-1846P4MEDIUMCVSS 4.3≤ 7.02008-04-16
CVE-2008-1846 [MEDIUM] CWE-79 CVE-2008-1846: The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HT
The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
nvd
CVE-2010-1609P4MEDIUMCVSS 4.3v4.0v7.02010-04-29
CVE-2010-1609 [MEDIUM] CWE-79 CVE-2010-1609: Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 all
Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2016-7437P4LOWCVSS 3.3v7.402016-10-13
CVE-2016-7437 [LOW] CVE-2016-7437: SAP Netweaver 7.40 improperly logs (1) DUI and (2) DUJ events in the SAP Security Audit Log as non-c
SAP Netweaver 7.40 improperly logs (1) DUI and (2) DUJ events in the SAP Security Audit Log as non-critical, which might allow local users to hide rejected attempts to execute RFC function callbacks by leveraging filtering of non-critical events in audit analysis reports, aka SAP Security Note 2252312.
nvd
CVE-2023-32114P4LOWCVSS 2.7v702v731+9 more2023-06-13
CVE-2023-32114 [LOW] CWE-732 CVE-2023-32114: SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755,
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead to a limited impact on Availability with No impact on Confidentiality and In
nvd
← Previous5 / 5