cbcvebase.

Sap Netweaver Application Server Java vulnerabilities

68 known vulnerabilities affecting sap/netweaver_application_server_java.

Total CVEs
68
CISA KEV
7
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH20MEDIUM36LOW1

Vulnerabilities

Page 4 of 4
CVE-2018-2504P4MEDIUMCVSS 6.1v7.10v7.11+5 more2018-12-11
CVE-2018-2504 [MEDIUM] CWE-79 CVE-2018-2504: SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
nvd
CVE-2019-0275P4MEDIUMCVSS 5.4≥ 7.10, ≤ 7.11v7.20+4 more2019-03-12
CVE-2019-0275 [MEDIUM] CWE-79 CVE-2019-0275: SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability.
nvd
CVE-2017-11458P4MEDIUMCVSS 6.1v7.302017-07-25
CVE-2017-11458 [MEDIUM] CWE-79 CVE-2017-11458: Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAV Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
nvd
CVE-2019-0391P4MEDIUMCVSS 4.3v7.10v7.20+4 more2019-11-13
CVE-2019-0391 [MEDIUM] CVE-2019-0391: Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) all Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2020-26816P4MEDIUMCVSS 4.5v7.10v7.11+5 more2020-12-09
CVE-2020-26816 [MEDIUM] CWE-312 CVE-2020-26816: SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys becau
nvd
CVE-2021-33689P4MEDIUMCVSS 4.3v7.502021-07-14
CVE-2021-33689 [MEDIUM] CWE-778 CVE-2021-33689: When user with insufficient privileges tries to access any application in SAP NetWeaver Administrato When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
nvd
CVE-2021-21492P4MEDIUMCVSS 4.3v7.10v7.11+5 more2021-04-13
CVE-2021-21492 [MEDIUM] CWE-290 CVE-2021-21492: SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
nvd
CVE-2026-23686P4LOWCVSS 3.4v7.502026-02-10
CVE-2026-23686 [LOW] CWE-113 CVE-2026-23686: Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated att Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled
nvd
Sap Netweaver Application Server Java vulnerabilities | cvebase