CVEs (69)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Application Server Java Jun 17, 2026 Feb 12, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 13, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 13, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execu...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Sep 10, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick t...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 10, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script fil...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 10, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Dec 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in version...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Dec 11, 2018 N/A· v4 7.4 HIGH· v3 3.3 LOW· v2 By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30,...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Dec 11, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50. |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Sep 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability. |
1Sap 1Netweaver Application Server Java May 13, 2026 Sep 19, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181. |
1Sap 1Netweaver Application Server Java Apr 22, 2026 Aug 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 Jul 25, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 Jul 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtr...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 Apr 14, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Sec...Show more |
1Sap 1Netweaver Application Server Java May 13, 2026 Apr 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated...Show more |
1Sap 1Netweaver Application Server Java Apr 21, 2026 Nov 23, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. |