Home/Product/sap netweaver application server java
Product

sap netweaver application server java

68 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-23686
all versions
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative acce
3.4LOW
CVE-2025-42926
all versions
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files
5.3MEDIUM
CVE-2024-34688
all versions
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on th
7.5HIGH
CVE-2024-28164
all versions
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the serve
5.3MEDIUM
CVE-2024-22127
all versions
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to
9.1CRITICAL
CVE-2024-24743
all versions
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request w
8.6HIGH
CVE-2024-22126
all versions
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incom
6.1MEDIUM
CVE-2023-42480
all versions
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to ide
5.3MEDIUM
CVE-2023-42477
all versions
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable
6.5MEDIUM
CVE-2023-40309
all versions
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks fo
9.8CRITICAL
CVE-2023-40308
all versions
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory c
7.5HIGH
CVE-2023-24526
all versions
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functio
5.3MEDIUM
CVE-2022-41262
all versions
Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated atta
6.1MEDIUM
CVE-2022-26103
all versions
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information w
5.3MEDIUM
CVE-2022-22533
all versions
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22,
7.5HIGH
CVE-2022-22532
all versions
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.2
9.8CRITICAL
CVE-2021-37535
all versions
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform nece
9.8CRITICAL
CVE-2021-33689
all versions
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications)
4.3MEDIUM
CVE-2021-33687
all versions
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of t
4.9MEDIUM
CVE-2021-33670
all versions
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacke
7.5HIGH
CVE-2021-27601
all versions
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on
5.4MEDIUM
CVE-2021-27598
all versions
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statisti
5.3MEDIUM
CVE-2021-21492
all versions
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently va
4.3MEDIUM
CVE-2021-21485
all versions
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server f
6.5MEDIUM
CVE-2021-21491
all versions
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.
6.1MEDIUM
CVE-2020-26829
all versions
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections fro
10.0CRITICAL
CVE-2020-26826
all versions
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (inclu
6.5MEDIUM
CVE-2020-26816
all versions
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in th
4.5MEDIUM
CVE-2020-26820
all versions
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use
7.2HIGH
CVE-2020-6365
all versions
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker t
6.1MEDIUM
CVE-2020-6319
all versions
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker
6.1MEDIUM
CVE-2020-6313
all versions
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inpu
6.5MEDIUM
CVE-2020-6309
all versions
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not
7.5HIGH
CVE-2020-6287
all versions
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which
10.0CRITICAL
CVE-2020-6286
all versions
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard),
5.3MEDIUM
CVE-2020-6282
all versions
SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (I
5.8MEDIUM
CVE-2020-6263
all versions
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.2
9.8CRITICAL
CVE-2020-6224
all versions
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator pri
6.2MEDIUM
CVE-2020-6202
all versions
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not suffi
7.2HIGH
CVE-2020-6190
all versions
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable i
5.8MEDIUM
CVE-2019-0391
all versions
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access info
4.3MEDIUM
CVE-2019-0389
all versions
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5),
8.8HIGH
CVE-2019-0355
all versions
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR
7.2HIGH
CVE-2019-0345
all versions
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overv
9.8CRITICAL
CVE-2019-0327
all versions
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, ve
7.2HIGH
CVE-2019-0318
all versions
Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53,
5.3MEDIUM
CVE-2019-0275
>= 7.10 and <= 7.11
SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40
5.4MEDIUM
CVE-2018-2504
all versions
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host
6.1MEDIUM
CVE-2018-2503
all versions
By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be prote
7.4HIGH
CVE-2018-2492
all versions
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. T
7.1HIGH
CVE-2018-2452
all versions
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-contro
6.1MEDIUM
CVE-2017-14581
>= 7.00 and <= 7.50
The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (servic
7.5HIGH
CVE-2017-12637
all versions
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java
7.5HIGH
CVE-2017-11458
all versions
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers
6.1MEDIUM
CVE-2017-11457
all versions
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to rea
6.5MEDIUM
CVE-2017-8913
all versions
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External E
8.8HIGH
CVE-2017-7717
all versions
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote
8.8HIGH
CVE-2016-10304
all versions
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-m
6.5MEDIUM
CVE-2016-9563
all versions
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the
6.5MEDIUM
CVE-2016-9562
all versions
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HT
7.5HIGH
CVE-2010-5326
<= 7.30
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, whic
10.0CRITICAL
CVE-2015-8840
all versions
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated
8.8HIGH
CVE-2016-3976
>= 7.10 and <= 7.50
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a .
7.5HIGH
CVE-2016-3975
>= 7.10 and <= 7.50
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web
6.1MEDIUM
CVE-2016-3974
>= 7.10 and <= 7.50
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attacke
9.1CRITICAL
CVE-2016-3973
>= 7.10 and <= 7.50
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote
5.3MEDIUM
CVE-2016-2388
>= 7.10 and <= 7.50
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via
5.3MEDIUM
CVE-2016-2386
all versions
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin