Sap Web Application Server vulnerabilities

10 known vulnerabilities affecting sap/sap_web_application_server.

Total CVEs
10
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM9

Vulnerabilities

Page 1 of 1
CVE-2008-2421MEDIUMCVSS 4.3PoCv7.02008-05-23
CVE-2008-2421 [MEDIUM] CWE-79 CVE-2008-2421: Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.
nvd
CVE-2007-3615HIGHCVSS 7.8v6.10v6.20+3 more2007-07-06
CVE-2007-3615 [HIGH] CVE-2007-3615: Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7. Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attackers to cause a denial of service (process crash) via a URI of a certain length that contains a sap-isc-key parameter, related to configuration of a web cache.
nvd
CVE-2006-6011MEDIUMCVSS 5.0v6.402006-11-21
CVE-2006-6011 [MEDIUM] CVE-2006-6011: Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash) via a certain UDP packet to port 64999, aka "two bytes UDP crash," a different vulnerability than CVE-2006-5785.
nvd
CVE-2006-5784MEDIUMCVSS 4.6PoCv6.40v7.002006-11-07
CVE-2006-5784 [MEDIUM] CVE-2006-5784: Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7. Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by local users to access a named pipe as the SAPServiceJ2E user.
nvd
CVE-2006-5785MEDIUMCVSS 5.0v6.40v7.002006-11-07
CVE-2006-5785 [MEDIUM] CVE-2006-5785: Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of service (enserver.exe crash) via a 0x72F2 sequence on UDP port 64999.
nvd
CVE-2006-1039MEDIUMCVSS 6.4PoCv6.10v6.20+1 more2006-03-07
CVE-2006-1039 [MEDIUM] CWE-94 CVE-2006-1039: SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary byt SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.
nvd
CVE-2005-3634MEDIUMCVSS 5.0PoCv6.10v6.20+2 more2005-11-16
CVE-2005-3634 [MEDIUM] CVE-2005-3634: frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
nvd
CVE-2005-3633MEDIUMCVSS 5.0v6.10v6.20+2 more2005-11-16
CVE-2005-3633 [MEDIUM] CVE-2005-3633: HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 throu HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-exiturl parameter.
nvd
CVE-2005-3636MEDIUMCVSS 4.3PoCv6.102005-11-16
CVE-2005-3636 [MEDIUM] CVE-2005-3636: Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote atta Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.
nvd
CVE-2005-3635MEDIUMCVSS 4.3PoCv6.10v6.20+2 more2005-11-16
CVE-2005-3635 [MEDIUM] CVE-2005-3635: Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.
nvd