VYPR

NetWeaver Enterprise Portal

by SAP

CVEs (24)

  • CVE-2021-33687MedJul 14, 2021
    risk 0.32cvss 4.9epss 0.02

    SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.

  • CVE-2024-44120MedSep 10, 2024
    risk 0.31cvss 4.7epss 0.00

    SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times…

  • CVE-2021-21489MedSep 14, 2021
    risk 0.31cvss 4.8epss 0.01

    SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious…

  • CVE-2026-44759MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information,…

Page 2 of 2