cbcvebase.

Sap Netweaver Application Server Java vulnerabilities

68 known vulnerabilities affecting sap/netweaver_application_server_java.

Total CVEs
68
CISA KEV
7
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH20MEDIUM36LOW1

Vulnerabilities

Page 2 of 4
CVE-2017-8913P3HIGHCVSS 8.8v7.502017-05-23
CVE-2017-8913 [HIGH] CWE-611 CVE-2017-8913: The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated u The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.
nvd
CVE-2019-0327P3HIGHCVSS 7.2v7.10v7.20+4 more2019-07-10
CVE-2019-0327 [HIGH] CWE-434 CVE-2019-0327: SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.
nvd
CVE-2019-0355P3HIGHCVSS 7.2v7.10v7.20+4 more2019-09-10
CVE-2019-0355 [HIGH] CWE-94 CVE-2019-0355: SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7. SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
nvd
CVE-2020-6309P3HIGHCVSS 7.5v7.10v7.11+5 more2020-08-12
CVE-2020-6309 [HIGH] CWE-306 CVE-2020-6309: SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2 SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.
nvd
CVE-2024-22126P3HIGHCVSS 8.8v7.502024-02-13
CVE-2024-22126 [HIGH] CWE-79 CVE-2024-22126: The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability.
nvd
CVE-2021-33670P3HIGHCVSS 7.5v7.10v7.11+5 more2021-07-14
CVE-2021-33670 [HIGH] CVE-2021-33670: SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
nvd
CVE-2022-22533P3HIGHCVSS 7.5v7.22v7.49+7 more2022-02-09
CVE-2022-22533 [HIGH] CWE-416 CVE-2022-22533: Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7 Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system un
nvd
CVE-2023-40308P3HIGHCVSS 7.5vkernel_7.22vkernel_7.53+14 more2023-09-12
CVE-2023-40308 [HIGH] CWE-787 CVE-2023-40308: SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to a SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
nvd
CVE-2024-34688P3HIGHCVSS 7.5vmmr_server_7.52024-06-11
CVE-2024-34688 [HIGH] CWE-400 CVE-2024-34688: Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.
nvd
CVE-2020-6202P3HIGHCVSS 7.2v7.10v7.20+4 more2020-03-10
CVE-2020-6202 [HIGH] CWE-20 CVE-2020-6202: SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7. SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
nvd
CVE-2020-26826P3MEDIUMCVSS 6.5v7.31v7.40+1 more2020-12-09
CVE-2020-26826 [MEDIUM] CWE-434 CVE-2020-26826: Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an atta Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
nvd
CVE-2017-11457P3MEDIUMCVSS 6.5v7.502017-07-25
CVE-2017-11457 [MEDIUM] CWE-611 CVE-2017-11457: XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows rem XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.
nvd
CVE-2016-9562P3HIGHCVSS 7.5v7.402016-11-23
CVE-2016-9562 [HIGH] CWE-476 CVE-2016-9562: SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer excepti SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.
nvd
CVE-2018-2503P3HIGHCVSS 7.4v7.11v7.20+4 more2018-12-11
CVE-2018-2503 [HIGH] CWE-862 CVE-2018-2503: By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).
nvd
CVE-2023-42477P3MEDIUMCVSS 6.5v7.502023-10-10
CVE-2023-42477 [MEDIUM] CWE-918 CVE-2023-42477: SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a craf SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
nvd
CVE-2017-14581P4HIGHCVSS 7.5≥ 7.00, ≤ 7.502017-09-19
CVE-2017-14581 [HIGH] CVE-2017-14581: The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cau The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181.
nvd
CVE-2021-21485P4MEDIUMCVSS 6.5v7.10v7.20+4 more2021-04-13
CVE-2021-21485 [MEDIUM] CVE-2021-21485: An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.
nvd
CVE-2020-6313P4MEDIUMCVSS 6.5v7.30v7.31+2 more2020-09-09
CVE-2020-6313 [MEDIUM] CWE-79 CVE-2020-6313: SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficient SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting.
nvd
CVE-2026-27674P4MEDIUMCVSS 6.1v7.502026-04-14
CVE-2026-27674 [MEDIUM] CWE-94 CVE-2026-27674: Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in t
nvd
CVE-2018-2492P4HIGHCVSS 7.1v7.20v7.30+3 more2018-12-11
CVE-2018-2492 [HIGH] CWE-611 CVE-2018-2492: SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents receiv SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.
nvd
Sap Netweaver Application Server Java vulnerabilities | cvebase