cbcvebase.

Sap Se Sap Netweaver vulnerabilities

40 known vulnerabilities affecting sap_se/sap_netweaver.

Total CVEs
40
CISA KEV
3
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH9MEDIUM24LOW1

Vulnerabilities

Page 2 of 2
CVE-2022-22534P4MEDIUMCVSS 6.1v700v701+10 more2022-02-09
CVE-2022-22534 [MEDIUM] CWE-79 CVE-2022-22534: Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inje Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
nvd
CVE-2023-41367P4MEDIUMCVSS 5.3v7.502023-09-12
CVE-2023-41367 [MEDIUM] CWE-306 CVE-2023-41367: Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability imp
nvd
CVE-2024-27898P4MEDIUMCVSS 5.3v7.502024-04-09
CVE-2024-27898 [MEDIUM] CWE-918 CVE-2024-27898: SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafte SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on con
nvd
CVE-2020-6181P4MEDIUMCVSS 5.8v= 7.02v= 7.30+2 more2020-02-12
CVE-2020-6181 [MEDIUM] CVE-2020-6181: Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 7 Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
nvd
CVE-2025-31325P4MEDIUMCVSS 5.8vSAP_BASIS 7582025-06-10
CVE-2025-31325 [MEDIUM] CWE-79 CVE-2025-31325: Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauth Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the script executes in their browser, providing the attacker limited access to restricted information. The
nvd
CVE-2023-0021P4MEDIUMCVSS 6.1v700v701+4 more2023-03-14
CVE-2023-0021 [MEDIUM] CWE-79 CVE-2023-0021: Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, a Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially
nvd
CVE-2020-6326P4MEDIUMCVSS 5.4fixed in 7.30fixed in 7.31+2 more2020-09-09
CVE-2020-6326 [MEDIUM] CWE-79 CVE-2020-6326: SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting.
nvd
CVE-2022-26103P4MEDIUMCVSS 5.3fixed in 7.502022-03-10
CVE-2022-26103 [MEDIUM] CWE-862 CVE-2022-26103: Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an at Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
nvd
CVE-2024-25645P4MEDIUMCVSS 5.3v7.502024-03-12
CVE-2024-25645 [MEDIUM] CWE-732 CVE-2024-25645: Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to acces Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
nvd
CVE-2020-6193P4MEDIUMCVSS 6.1v= 7.30v= 7.31+2 more2020-02-12
CVE-2020-6193 [MEDIUM] CWE-79 CVE-2020-6193: SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthe SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2025-31331P4MEDIUMCVSS 4.3vSAP_ABA 700v701+13 more2025-04-08
CVE-2025-31331 [MEDIUM] CWE-863 CVE-2025-31331: SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of A SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiali
nvd
CVE-2021-38183P4MEDIUMCVSS 6.1fixed in 700fixed in 701+2 more2021-10-12
CVE-2021-38183 [MEDIUM] CWE-79 CVE-2021-38183: SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, al SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
nvd
CVE-2020-6185P4MEDIUMCVSS 5.4v= 7.402020-02-12
CVE-2020-6185 [MEDIUM] CWE-79 CVE-2020-6185: Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4 Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
nvd
CVE-2023-33984P4MEDIUMCVSS 5.4v7.502023-06-13
CVE-2023-33984 [MEDIUM] CWE-79 CVE-2023-33984: SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant message. Under certain circumstances, this could lead to Cross-Site Scripting vulnerability.
nvd
CVE-2025-42968P4MEDIUMCVSS 4.3vSAP_BW 700v701+16 more2025-07-08
CVE-2025-42968 [MEDIUM] CWE-862 CVE-2025-42968: SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function mo SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the
nvd
CVE-2025-42911P4MEDIUMCVSS 4.3vSAP_BASIS 700vSAP_BASIS 701+13 more2025-09-09
CVE-2025-42911 [MEDIUM] CWE-862 CVE-2025-42911: SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application
nvd
CVE-2020-6187P4MEDIUMCVSS 4.9v= 7.10v= 7.11+5 more2020-02-12
CVE-2020-6187 [MEDIUM] CWE-611 CVE-2020-6187: SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suffi SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
nvd
CVE-2020-6370P4MEDIUMCVSS 4.8fixed in 7.11fixed in 7.30+3 more2020-10-20
CVE-2020-6370 [MEDIUM] CWE-79 CVE-2020-6370: SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not suffic SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2026-23685P4MEDIUMCVSS 4.4vJ2EE-FRMW 7.502026-02-10
CVE-2026-23685 [MEDIUM] CWE-502 CVE-2026-23685: Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successfu
nvd
CVE-2023-32114P4LOWCVSS 2.7v702v731+9 more2023-06-13
CVE-2023-32114 [LOW] CWE-732 CVE-2023-32114: SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead to a limited impact on Availability with No impact on Confidentiality and In
nvd
Sap Se Sap Netweaver vulnerabilities | cvebase