CVEs (69)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter a...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization ch...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory l...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 10, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vuln...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 10.0 CRITICAL· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upl...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 4.5 MEDIUM· v3 2.7 LOW· v2 SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded form...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Oct 15, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Oct 15, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are other...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Sep 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Aug 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an at...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jun 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Apr 14, 2020 N/A· v4 6.2 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 10, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untruste...Show more |