threat
engine
.sh
Back
·
··:··
Home
/
Product
/
sap netweaver application server java
Product
sap netweaver application server java
68 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-23686
all versions
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative acce
3.4
LOW
CVE-2025-42926
all versions
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files
5.3
MEDIUM
CVE-2024-34688
all versions
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on th
7.5
HIGH
CVE-2024-28164
all versions
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the serve
5.3
MEDIUM
CVE-2024-22127
all versions
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to
9.1
CRITICAL
CVE-2024-24743
all versions
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request w
8.6
HIGH
CVE-2024-22126
all versions
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incom
6.1
MEDIUM
CVE-2023-42480
all versions
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to ide
5.3
MEDIUM
CVE-2023-42477
all versions
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable
6.5
MEDIUM
CVE-2023-40309
all versions
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks fo
9.8
CRITICAL
CVE-2023-40308
all versions
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory c
7.5
HIGH
CVE-2023-24526
all versions
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functio
5.3
MEDIUM
CVE-2022-41262
all versions
Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated atta
6.1
MEDIUM
CVE-2022-26103
all versions
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information w
5.3
MEDIUM
CVE-2022-22533
all versions
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22,
7.5
HIGH
CVE-2022-22532
all versions
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.2
9.8
CRITICAL
CVE-2021-37535
all versions
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform nece
9.8
CRITICAL
CVE-2021-33689
all versions
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications)
4.3
MEDIUM
CVE-2021-33687
all versions
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of t
4.9
MEDIUM
CVE-2021-33670
all versions
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacke
7.5
HIGH
CVE-2021-27601
all versions
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on
5.4
MEDIUM
CVE-2021-27598
all versions
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statisti
5.3
MEDIUM
CVE-2021-21492
all versions
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently va
4.3
MEDIUM
CVE-2021-21485
all versions
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server f
6.5
MEDIUM
CVE-2021-21491
all versions
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.
6.1
MEDIUM
CVE-2020-26829
all versions
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections fro
10.0
CRITICAL
CVE-2020-26826
all versions
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (inclu
6.5
MEDIUM
CVE-2020-26816
all versions
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in th
4.5
MEDIUM
CVE-2020-26820
all versions
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use
7.2
HIGH
CVE-2020-6365
all versions
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker t
6.1
MEDIUM
CVE-2020-6319
all versions
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker
6.1
MEDIUM
CVE-2020-6313
all versions
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inpu
6.5
MEDIUM
CVE-2020-6309
all versions
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not
7.5
HIGH
CVE-2020-6287
all versions
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which
10.0
CRITICAL
CVE-2020-6286
all versions
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard),
5.3
MEDIUM
CVE-2020-6282
all versions
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (I
5.8
MEDIUM
CVE-2020-6263
all versions
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.2
9.8
CRITICAL
CVE-2020-6224
all versions
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator pri
6.2
MEDIUM
CVE-2020-6202
all versions
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not suffi
7.2
HIGH
CVE-2020-6190
all versions
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable i
5.8
MEDIUM
CVE-2019-0391
all versions
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access info
4.3
MEDIUM
CVE-2019-0389
all versions
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5),
8.8
HIGH
CVE-2019-0355
all versions
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR
7.2
HIGH
CVE-2019-0345
all versions
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overv
9.8
CRITICAL
CVE-2019-0327
all versions
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, ve
7.2
HIGH
CVE-2019-0318
all versions
Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53,
5.3
MEDIUM
CVE-2019-0275
>= 7.10 and <= 7.11
SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40
5.4
MEDIUM
CVE-2018-2504
all versions
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host
6.1
MEDIUM
CVE-2018-2503
all versions
By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be prote
7.4
HIGH
CVE-2018-2492
all versions
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. T
7.1
HIGH
CVE-2018-2452
all versions
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-contro
6.1
MEDIUM
CVE-2017-14581
>= 7.00 and <= 7.50
The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (servic
7.5
HIGH
CVE-2017-12637
all versions
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java
7.5
HIGH
CVE-2017-11458
all versions
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers
6.1
MEDIUM
CVE-2017-11457
all versions
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to rea
6.5
MEDIUM
CVE-2017-8913
all versions
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External E
8.8
HIGH
CVE-2017-7717
all versions
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote
8.8
HIGH
CVE-2016-10304
all versions
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-m
6.5
MEDIUM
CVE-2016-9563
all versions
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the
6.5
MEDIUM
CVE-2016-9562
all versions
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HT
7.5
HIGH
CVE-2010-5326
<= 7.30
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, whic
10.0
CRITICAL
CVE-2015-8840
all versions
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated
8.8
HIGH
CVE-2016-3976
>= 7.10 and <= 7.50
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a .
7.5
HIGH
CVE-2016-3975
>= 7.10 and <= 7.50
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web
6.1
MEDIUM
CVE-2016-3974
>= 7.10 and <= 7.50
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attacke
9.1
CRITICAL
CVE-2016-3973
>= 7.10 and <= 7.50
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote
5.3
MEDIUM
CVE-2016-2388
>= 7.10 and <= 7.50
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via
5.3
MEDIUM
CVE-2016-2386
all versions
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin