VYPR

Netweaver

by SAP

CVEs (133)

  • CVE-2018-2477HigNov 13, 2018
    risk 0.57cvss 8.8epss 0.02

    Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2018-2462HigSep 11, 2018
    risk 0.57cvss 8.8epss 0.02

    In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2018-2363HigJan 9, 2018
    risk 0.57cvss 8.8epss 0.02

    SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially…

  • CVE-2016-4014HigApr 14, 2016
    risk 0.56cvss 8.6epss 0.05

    XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.

  • CVE-2016-2389HigFeb 16, 2016
    risk 0.55cvss 7.5epss 0.41

    Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security…

  • CVE-2018-2494HigDec 11, 2018
    risk 0.52cvss 8.0epss 0.01

    Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.

  • CVE-2025-42874HigDec 9, 2025
    risk 0.51cvss 7.9epss 0.00

    SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction…

  • CVE-2022-29616HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.

  • CVE-2022-28773HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.

  • CVE-2022-28772HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22,…

  • CVE-2013-1593HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN.

  • CVE-2017-9845HigJul 12, 2017
    risk 0.49cvss 7.5epss 0.03

    disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.

  • CVE-2017-9844HigJul 12, 2017
    risk 0.49cvss 7.5epss 0.06

    SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of…

  • CVE-2017-5372HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.04

    The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4)…

  • CVE-2016-3635HigOct 13, 2016
    risk 0.49cvss 7.5epss 0.02

    SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication…

  • CVE-2016-4551HigOct 5, 2016
    risk 0.49cvss 7.5epss 0.01

    The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.

  • CVE-2016-4015HigApr 14, 2016
    risk 0.49cvss 7.5epss 0.03

    The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.

  • CVE-2024-54197HigDec 10, 2024
    risk 0.47cvss 7.2epss 0.00

    SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a…

  • CVE-2020-6318HigSep 9, 2020
    risk 0.47cvss 7.2epss 0.06

    A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products,…

  • CVE-2023-26461MedMar 14, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows…

Page 2 of 7