Sap Se Sap Netweaver Enterprise Portal vulnerabilities
22 known vulnerabilities affecting sap_se/sap_netweaver_enterprise_portal.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM21
Vulnerabilities
Page 2 of 2
CVE-2024-44120P4MEDIUMCVSS 4.7v7.502024-09-10
CVE-2024-44120 [MEDIUM] CWE-79 CVE-2024-44120: SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient
SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browse
nvd
CVE-2021-21489P4MEDIUMCVSS 4.8fixed in 7.10fixed in 7.11+5 more2021-09-14
CVE-2021-21489 [MEDIUM] CWE-79 CVE-2021-21489: SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suffic
SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious script on the portal. The execution of the script content by a victim regist
nvd
← Previous2 / 2