cbcvebase.

Sap Netweaver Application Server Java vulnerabilities

68 known vulnerabilities affecting sap/netweaver_application_server_java.

Total CVEs
68
CISA KEV
7
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH20MEDIUM36LOW1

Vulnerabilities

Page 3 of 4
CVE-2020-6282P4MEDIUMCVSS 5.8v7.10v7.11+5 more2020-07-14
CVE-2020-6282 [MEDIUM] CWE-918 CVE-2020-6282: SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls th
nvd
CVE-2025-42926P4MEDIUMCVSS 5.3v7.502025-09-09
CVE-2025-42926 [MEDIUM] CWE-306 CVE-2025-42926: SAP NetWeaver Application Server Java does not perform an authentication check when an attacker atte SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidenti
nvd
CVE-2020-6224P4MEDIUMCVSS 6.2v7.10v7.11+5 more2020-04-14
CVE-2020-6224 [MEDIUM] CWE-532 CVE-2020-6224: SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an a SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
nvd
CVE-2022-41262P4MEDIUMCVSS 6.1v7.502022-12-12
CVE-2022-41262 [MEDIUM] CWE-79 CVE-2022-41262: Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.
nvd
CVE-2019-0318P4MEDIUMCVSS 5.3v7.21v7.22+3 more2019-07-10
CVE-2019-0318 [MEDIUM] CVE-2019-0318: Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.2 Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2023-24526P4MEDIUMCVSS 5.3v7.502023-03-14
CVE-2023-24526 [MEDIUM] CWE-306 CVE-2023-24526: SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any aut SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive server data.
nvd
CVE-2024-28164P4MEDIUMCVSS 5.3vgp-core_7.52024-06-11
CVE-2024-28164 [MEDIUM] CWE-200 CVE-2024-28164: SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensiti SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.
nvd
CVE-2016-10304P4MEDIUMCVSS 6.5v7.502017-04-10
CVE-2016-10304 [MEDIUM] CWE-502 CVE-2016-10304: The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.
nvd
CVE-2020-6365P4MEDIUMCVSS 6.1v7.10v7.11+5 more2020-10-15
CVE-2020-6365 [MEDIUM] CWE-601 CVE-2020-6365: SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an una SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect users to untrusted web pages containi
nvd
CVE-2020-6319P4MEDIUMCVSS 6.1v7.10v7.11+5 more2020-10-15
CVE-2020-6319 [MEDIUM] CWE-79 CVE-2020-6319: SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allow SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successful exploitation an attacker can steal authentication information of the user, such as data relating to hi
nvd
CVE-2021-21491P4MEDIUMCVSS 6.1v7.00v7.10+6 more2021-03-10
CVE-2021-21491 [MEDIUM] CWE-601 CVE-2021-21491: SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7. SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
nvd
CVE-2016-3973P4MEDIUMCVSS 5.3≥ 7.10, ≤ 7.502016-04-07
CVE-2016-3973 [MEDIUM] CWE-200 CVE-2016-3973: The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.
nvd
CVE-2021-27598P4MEDIUMCVSS 5.3v7.31v7.40+1 more2021-04-13
CVE-2021-27598 [MEDIUM] CWE-284 CVE-2021-27598: SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
nvd
CVE-2023-42480P4MEDIUMCVSS 5.3v7.502023-11-14
CVE-2023-42480 [MEDIUM] CWE-307 CVE-2023-42480: The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
nvd
CVE-2020-6190P4MEDIUMCVSS 5.8v7.30v7.31+2 more2020-02-12
CVE-2020-6190 [MEDIUM] CWE-200 CVE-2020-6190: Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
nvd
CVE-2022-26103P4MEDIUMCVSS 5.3v7.502022-03-10
CVE-2022-26103 [MEDIUM] CWE-862 CVE-2022-26103: Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an at Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
nvd
CVE-2016-3975P4MEDIUMCVSS 6.1≥ 7.10, ≤ 7.502016-04-07
CVE-2016-3975 [MEDIUM] CWE-79 CVE-2016-3975: Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote atta Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note 2238375.
nvd
CVE-2018-2452P4MEDIUMCVSS 6.1v7.10v7.11+5 more2018-09-11
CVE-2018-2452 [MEDIUM] CWE-79 CVE-2018-2452: The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not s The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.
nvd
CVE-2021-27601P4MEDIUMCVSS 5.4v7.10v7.11+4 more2021-04-13
CVE-2021-27601 [MEDIUM] CWE-79 CVE-2021-27601: SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacke SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.
nvd
CVE-2021-33687P4MEDIUMCVSS 4.9v7.10v7.20+4 more2021-07-14
CVE-2021-33687 [MEDIUM] CWE-200 CVE-2021-33687: SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sen SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
nvd
Sap Netweaver Application Server Java vulnerabilities | cvebase