Sap Netweaver Application Server Java vulnerabilities
68 known vulnerabilities affecting sap/netweaver_application_server_java.
Total CVEs
68
CISA KEV
7
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH20MEDIUM36LOW1
Vulnerabilities
Page 4 of 4
CVE-2018-2504P4MEDIUMCVSS 6.1v7.10v7.11+5 more2018-12-11
CVE-2018-2504 [MEDIUM] CWE-79 CVE-2018-2504: SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
nvd
CVE-2019-0275P4MEDIUMCVSS 5.4≥ 7.10, ≤ 7.11v7.20+4 more2019-03-12
CVE-2019-0275 [MEDIUM] CWE-79 CVE-2019-0275: SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to
SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability.
nvd
CVE-2017-11458P4MEDIUMCVSS 6.1v7.302017-07-25
CVE-2017-11458 [MEDIUM] CWE-79 CVE-2017-11458: Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAV
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
nvd
CVE-2019-0391P4MEDIUMCVSS 4.3v7.10v7.20+4 more2019-11-13
CVE-2019-0391 [MEDIUM] CVE-2019-0391: Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) all
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2020-26816P4MEDIUMCVSS 4.5v7.10v7.11+5 more2020-12-09
CVE-2020-26816 [MEDIUM] CWE-312 CVE-2020-26816: SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys becau
nvd
CVE-2021-33689P4MEDIUMCVSS 4.3v7.502021-07-14
CVE-2021-33689 [MEDIUM] CWE-778 CVE-2021-33689: When user with insufficient privileges tries to access any application in SAP NetWeaver Administrato
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
nvd
CVE-2021-21492P4MEDIUMCVSS 4.3v7.10v7.11+5 more2021-04-13
CVE-2021-21492 [MEDIUM] CWE-290 CVE-2021-21492: SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40,
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
nvd
CVE-2026-23686P4LOWCVSS 3.4v7.502026-02-10
CVE-2026-23686 [LOW] CWE-113 CVE-2026-23686: Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated att
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled
nvd
← Previous4 / 4