Sap Netweaver Application Server Java vulnerabilities
68 known vulnerabilities affecting sap/netweaver_application_server_java.
Total CVEs
68
CISA KEV
7
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH20MEDIUM36LOW1
Vulnerabilities
Page 1 of 4
CVE-2020-6287P1CRITICALCVSS 10.0KEVPoCv7.30v7.31+2 more2020-07-14
CVE-2020-6287 [CRITICAL] CWE-306 CVE-2020-6287: SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising C
nvd
CVE-2016-2386P1CRITICALCVSS 9.8KEVPoCv7.402016-02-16
CVE-2016-2386 [CRITICAL] CWE-89 CVE-2016-2386: SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attac
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
nvd
CVE-2017-12637P1HIGHCVSS 7.5KEVPoCv7.502017-08-07
CVE-2017-12637 [HIGH] CWE-22 CVE-2017-12637: Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetW
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.
nvd
CVE-2016-3976P1HIGHCVSS 7.5KEVPoC≥ 7.10, ≤ 7.502016-04-07
CVE-2016-3976 [HIGH] CWE-22 CVE-2016-3976: Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers t
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
nvd
CVE-2016-2388P2MEDIUMCVSS 5.3KEVPoC≥ 7.10, ≤ 7.502016-02-16
CVE-2016-2388 [MEDIUM] CWE-200 CVE-2016-2388: The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
nvd
CVE-2010-5326P1CRITICALCVSS 10.0KEV≤ 7.302016-05-13
CVE-2010-5326 [CRITICAL] CWE-306 CVE-2010-5326: The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does no
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.
nvd
CVE-2016-9563P2MEDIUMCVSS 6.5KEVv7.502016-11-23
CVE-2016-9563 [MEDIUM] CWE-611 CVE-2016-9563: BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML Externa
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
nvd
CVE-2020-6286P1MEDIUMCVSS 5.3ExploitedPoCv7.30v7.31+2 more2020-07-14
CVE-2020-6286 [MEDIUM] CWE-22 CVE-2020-6286: The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS J
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
nvd
CVE-2016-3974P2CRITICALCVSS 9.1PoC≥ 7.10, ≤ 7.502016-04-07
CVE-2016-3974 [CRITICAL] CWE-611 CVE-2016-3974: XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 thr
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
nvd
CVE-2020-26829P2CRITICALCVSS 10.0v7.11v7.20+4 more2020-12-09
CVE-2020-26829 [CRITICAL] CWE-306 CVE-2020-26829: SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, al
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke
nvd
CVE-2019-0345P2CRITICALCVSS 9.8v7.30v7.31+2 more2019-08-14
CVE-2019-0345 [CRITICAL] CWE-918 CVE-2019-0345: A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Ja
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request
nvd
CVE-2022-22532P2CRITICALCVSS 9.8v7.22v7.49+7 more2022-02-09
CVE-2022-22532 [CRITICAL] CWE-444 CVE-2022-22532: In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be executed and hence execute functi
nvd
CVE-2020-6263P3CRITICALCVSS 9.8v7.00v7.01+9 more2020-06-10
CVE-2020-6263 [CRITICAL] CWE-306 CVE-2020-6263: Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.
nvd
CVE-2023-40309P3CRITICALCVSS 9.8vkernel_7.22vkernel_7.53+14 more2023-09-12
CVE-2023-40309 [CRITICAL] CWE-863 CVE-2023-40309: SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as r
nvd
CVE-2024-22127P3CRITICALCVSS 9.1v7.52024-03-12
CVE-2024-22127 [CRITICAL] CWE-77 CVE-2024-22127: SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an att
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the applicat
nvd
CVE-2017-7717P3HIGHCVSS 8.8v7.402017-04-14
CVE-2017-7717 [HIGH] CWE-89 CVE-2017-7717: SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWea
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
nvd
CVE-2021-37535P3CRITICALCVSS 9.8v7.11v7.20+4 more2021-09-14
CVE-2021-37535 [CRITICAL] CWE-862 CVE-2021-37535: SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.4
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
nvd
CVE-2020-26820P3HIGHCVSS 7.2v7.20v7.30+3 more2020-11-10
CVE-2020-26820 [HIGH] CWE-434 CVE-2020-26820: SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authentica
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file le
nvd
CVE-2019-0389P3HIGHCVSS 8.8v7.1v7.2+4 more2019-11-13
CVE-2019-0389 [HIGH] CVE-2019-0389: An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
nvd
CVE-2024-24743P3HIGHCVSS 7.5v7.502024-02-13
CVE-2024-24743 [HIGH] CWE-611 CVE-2024-24743: SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker t
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability is not affected.
nvd
1 / 4Next →