VYPR

Netweaver Application Server Java

by SAP

CVEs (95)

  • CVE-2021-33689MedJul 14, 2021
    risk 0.28cvss 4.3epss 0.01

    When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.

  • CVE-2021-21492MedApr 13, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

  • CVE-2015-7968MedMar 9, 2020
    risk 0.28cvss 4.3epss 0.01

    nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.

  • CVE-2019-0391MedNov 13, 2019
    risk 0.28cvss 4.3epss 0.01

    Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.

  • CVE-2025-42978LowJul 8, 2025
    risk 0.23cvss 3.5epss 0.00

    The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might…

  • CVE-2026-23686LowFeb 10, 2026
    risk 0.22cvss 3.4epss 0.00

    Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries…

  • CVE-2026-0510LowJan 13, 2026
    risk 0.20cvss 3.0epss 0.00

    The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific…

  • CVE-2026-44752HigJul 14, 2026
    risk 0.00cvss 8.2epss 0.00

    SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify…

  • CVE-2015-4158Jun 2, 2015
    risk 0.00cvss epss 0.02

    SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661.

  • CVE-2015-2282Jun 2, 2015
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and…

  • CVE-2015-2278Jun 2, 2015
    risk 0.00cvss epss 0.02

    The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows…

  • CVE-2015-4091May 26, 2015
    risk 0.00cvss epss 0.03

    XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851.

  • CVE-2014-8590Nov 4, 2014
    risk 0.00cvss epss 0.02

    XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request.

  • CVE-2014-3133Apr 30, 2014
    risk 0.00cvss epss 0.02

    SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to SystemSelection.

  • CVE-2009-2932Aug 21, 2009
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.

Page 5 of 5