VYPR

ENGINEAPI

by SAP

CVEs (2)

  • CVE-2020-6309HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.02

    SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service.

  • CVE-2019-0327HigJul 10, 2019
    risk 0.47cvss 7.2epss 0.02

    SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.