cbcvebase.

Sap Se Sap Netweaver As Java vulnerabilities

30 known vulnerabilities affecting sap_se/sap_netweaver_as_java.

Total CVEs
30
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH6MEDIUM18LOW1

Vulnerabilities

Page 2 of 2
CVE-2026-44746P4MEDIUMCVSS 6.1vBI_UDI 7.502026-06-09
CVE-2026-44746 [MEDIUM] CWE-79 CVE-2026-44746: Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser. This cou
nvd
CVE-2020-6190P4MEDIUMCVSS 5.8v= 7.30v= 7.31+2 more2020-02-12
CVE-2020-6190 [MEDIUM] CWE-200 CVE-2020-6190: Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
nvd
CVE-2021-33687P4MEDIUMCVSS 4.9fixed in 7.10fixed in 7.20+4 more2021-07-14
CVE-2021-33687 [MEDIUM] CWE-200 CVE-2021-33687: SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sen SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
nvd
CVE-2025-42925P4MEDIUMCVSS 4.3vSERVERCORE 7.502025-09-09
CVE-2025-42925 [MEDIUM] CWE-341 CVE-2025-42925: Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP serv Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could determine a desired identifier whi
nvd
CVE-2019-0391P4MEDIUMCVSS 4.3fixed in 7.10fixed in 7.20+4 more2019-11-13
CVE-2019-0391 [MEDIUM] CVE-2019-0391: Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) all Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2020-26816P4MEDIUMCVSS 4.5fixed in 7.10fixed in 7.11+5 more2020-12-09
CVE-2020-26816 [MEDIUM] CWE-312 CVE-2020-26816: SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys becau
nvd
CVE-2024-45280P4MEDIUMCVSS 4.8v7.502024-09-10
CVE-2024-45280 [MEDIUM] CWE-79 CVE-2024-45280: Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scrip Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
nvd
CVE-2021-33689P4MEDIUMCVSS 4.3fixed in 7.502021-07-14
CVE-2021-33689 [MEDIUM] CWE-778 CVE-2021-33689: When user with insufficient privileges tries to access any application in SAP NetWeaver Administrato When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
nvd
CVE-2025-0057P4MEDIUMCVSS 4.8vENGINEAPI 7.50vSERVERCORE 7.50+1 more2025-01-14
CVE-2025-0057 [MEDIUM] CWE-434 CVE-2025-0057: SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerab SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
nvd
CVE-2025-42927P4LOWCVSS 3.4vADSSAP 7.502025-09-09
CVE-2025-42927 [LOW] CWE-1395 CVE-2025-42927: SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version o SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on confidentiality and integrity, with no
nvd
Sap Se Sap Netweaver As Java vulnerabilities | cvebase