Sap Se Sap Netweaver As Java vulnerabilities
30 known vulnerabilities affecting sap_se/sap_netweaver_as_java.
Total CVEs
30
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH6MEDIUM18LOW1
Vulnerabilities
Page 1 of 2
CVE-2020-6287P1CRITICALCVSS 10.0KEVPoCfixed in 7.30fixed in 7.31+2 more2020-07-14
CVE-2020-6287 [CRITICAL] CWE-306 CVE-2020-6287: SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising C
nvd
CVE-2020-6286P1MEDIUMCVSS 5.3ExploitedPoCfixed in 7.30fixed in 7.31+2 more2020-07-14
CVE-2020-6286 [MEDIUM] CWE-22 CVE-2020-6286: The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS J
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
nvd
CVE-2020-26829P2CRITICALCVSS 10.0fixed in 7.11fixed in 7.20+4 more2020-12-09
CVE-2020-26829 [CRITICAL] CWE-306 CVE-2020-26829: SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, al
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke
nvd
CVE-2025-42922P2CRITICALCVSS 9.9vJ2EE-APPS 7.502025-09-09
CVE-2025-42922 [CRITICAL] CWE-94 CVE-2025-42922: SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.
nvd
CVE-2020-6263P3CRITICALCVSS 9.8fixed in SAP-JEECOR 7.00fixed in 7.01 SERVERCOR 7.10+11 more2020-06-10
CVE-2020-6263 [CRITICAL] CWE-306 CVE-2020-6263: Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.
nvd
CVE-2024-22127P3CRITICALCVSS 9.1v7.502024-03-12
CVE-2024-22127 [CRITICAL] CWE-77 CVE-2024-22127: SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an att
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the applicat
nvd
CVE-2020-26820P3HIGHCVSS 7.2fixed in 7.20fixed in 7.30+3 more2020-11-10
CVE-2020-26820 [HIGH] CWE-434 CVE-2020-26820: SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authentica
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file le
nvd
CVE-2021-21481P3HIGHCVSS 8.8fixed in 7.10fixed in 7.11+4 more2021-03-09
CVE-2021-21481 [HIGH] CWE-863 CVE-2021-21481: The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, a
nvd
CVE-2024-24743P3HIGHCVSS 7.5v7.502024-02-13
CVE-2024-24743 [HIGH] CWE-611 CVE-2024-24743: SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker t
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability is not affected.
nvd
CVE-2020-6309P3HIGHCVSS 7.5fixed in 7.10fixed in 7.11+5 more2020-08-12
CVE-2020-6309 [HIGH] CWE-306 CVE-2020-6309: SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.
nvd
CVE-2024-22126P3HIGHCVSS 8.8v7.502024-02-13
CVE-2024-22126 [HIGH] CWE-79 CVE-2024-22126: The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability.
nvd
CVE-2024-34688P3HIGHCVSS 7.5vMMR_SERVER 7.52024-06-11
CVE-2024-34688 [HIGH] CWE-400 CVE-2024-34688: Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers
Due to unrestricted access to the Meta Model
Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks
on the application, which may prevent legitimate users from accessing it. This
can result in no impact on confidentiality and integrity but a high impact on
the availability of the application.
nvd
CVE-2020-26826P3MEDIUMCVSS 6.5fixed in 7.31fixed in 7.40+1 more2020-12-09
CVE-2020-26826 [MEDIUM] CWE-434 CVE-2020-26826: Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an atta
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
nvd
CVE-2024-42372P3MEDIUMCVSS 6.5vLM-SLD 7.52024-11-12
CVE-2024-42372 [MEDIUM] CWE-862 CVE-2024-42372: Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthor
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
nvd
CVE-2023-42477P3MEDIUMCVSS 6.5v7.502023-10-10
CVE-2023-42477 [MEDIUM] CWE-918 CVE-2023-42477: SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a craf
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
nvd
CVE-2020-6313P4MEDIUMCVSS 6.5fixed in 7.30fixed in 7.31+2 more2020-09-09
CVE-2020-6313 [MEDIUM] CWE-79 CVE-2020-6313: SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficient
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to Stored Cross-Site Scripting.
nvd
CVE-2020-6282P4MEDIUMCVSS 5.8fixed in 7.10fixed in 7.11+5 more2020-07-14
CVE-2020-6282 [MEDIUM] CWE-918 CVE-2020-6282: SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls th
nvd
CVE-2024-47582P4MEDIUMCVSS 5.3vLM-CORE 7.502024-12-10
CVE-2024-47582 [MEDIUM] CWE-611 CVE-2024-47582: Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
nvd
CVE-2020-6224P4MEDIUMCVSS 6.2fixed in 7.10fixed in 7.11+5 more2020-04-14
CVE-2020-6224 [MEDIUM] CWE-532 CVE-2020-6224: SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an a
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
nvd
CVE-2024-28164P4MEDIUMCVSS 5.3vGP-CORE 7.52024-06-11
CVE-2024-28164 [MEDIUM] CWE-200 CVE-2024-28164: SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensiti
SAP NetWeaver AS Java (CAF - Guided Procedures)
allows an unauthenticated user to access non-sensitive information about the
server which would otherwise be restricted causing low impact on
confidentiality of the application.
nvd
1 / 2Next →