CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Development Infrastructure Jun 17, 2026 Jun 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code...Show more |
1Sap 1Netweaver Development Infrastructure Jun 17, 2026 Sep 15, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Serv...Show more |
1Sap 1Netweaver Development Infrastructure Jun 17, 2026 Sep 15, 2021 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infras...Show more |
1Sap 1Netweaver Development Infrastructure Apr 29, 2026 Nov 20, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by uploading a file with an executable extension via unspecified vectors. |