Skip to main content

Vendor/product archive

sap / netweaver CVEs

Beta · best-effort

104 CVEs tagged to sap / netweaver12 Critical, 24 High, 66 Medium, 2 Low, 0 Unrated.

CVE-2026-23685

Published Feb 10, 2026

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to th…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-42968

Published Jul 8, 2025

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP syste…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42999

Published May 13, 2025

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to…

CVSS 9.1 · Critical
evidence mentions
11
Buzz score
64.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-31324

Published Apr 24, 2025

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries th…

CVSS 10.0 · Critical
evidence mentions
33
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-27898

Published Apr 9, 2024

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25644

Published Mar 12, 2024

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality wit…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22124

Published Jan 9, 2024

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41367

Published Sep 12, 2023

Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36922

Published Jul 11, 2023

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system comman…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33985

Published Jun 13, 2023

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33984

Published Jun 13, 2023

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32114

Published Jun 13, 2023

SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-29186

Published Apr 11, 2023

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Dat…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-0021

Published Mar 14, 2023

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28217

Published Jun 13, 2022

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotecte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28773

Published Apr 12, 2022

Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28772

Published Apr 12, 2022

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Man…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22534

Published Feb 9, 2022

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38183

Published Oct 12, 2021

SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38163

Published Sep 14, 2021

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file o…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
47.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-21481

Published Mar 9, 2021

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6285

Published Jul 14, 2020

SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which woul…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6203

Published Mar 10, 2020

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provid…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6185

Published Feb 12, 2020

Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 104 CVEsPage 1 of 5