Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-42999 KEVEPSS 12% SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ… Netweaver Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-31324 KEVEPSS 100% SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma… Netweaver Mitigation only Fix from $2,3002025-04-24 CRITICAL 10.0 CVE-2022-22536 KEVEPSS 98% SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne… Content Server Mitigation only Fix from $2,3002022-02-09 HIGH 8.8 CVE-2021-38163 KEVEPSS 36% SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user… Netweaver Mitigation only Fix from $1,9502021-09-14 CRITICAL 10.0 CVE-2020-6287 KEVEPSS 95% SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… Netweaver Application Server Java Mitigation only Fix from $2,3002020-07-14 CRITICAL 9.8 CVE-2020-6207 KEVEPSS 98% SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic… Solution Manager Mitigation only Fix from $2,3002020-03-10 CRITICAL 9.8 CVE-2019-0344 KEVEPSS 7% Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex… Commerce Cloud Mitigation only Fix from $2,3002019-08-14 MEDIUM 6.6 CVE-2018-2380 KEVEPSS 29% SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus charact… Customer Relationship Management Mitigation only Fix from $1,6002018-03-01 HIGH 7.5 CVE-2017-12637 KEVEPSS 95% Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a… Netweaver Application Server Java Mitigation only Fix from $1,9502017-08-07 MEDIUM 6.5 CVE-2016-9563 KEVEPSS 24% BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi… Netweaver Application Server Java Mitigation only Fix from $1,6002016-11-23 CRITICAL 10.0 CVE-2010-5326 KEVEPSS 17% The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att… Netweaver Application Server Java after 7.30 Fix from $2,3002016-05-13 HIGH 7.5 CVE-2016-3976 KEVEPSS 47% Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backsla… Netweaver Application Server Java after 7.50 Fix from $1,9502016-04-07 MEDIUM 5.3 CVE-2016-2388 KEVEPSS 52% The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req… Netweaver Application Server Java after 7.50 Fix from $1,6002016-02-16 CRITICAL 9.8 CVE-2016-2386 KEVEPSS 71% SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspec… Netweaver Application Server Java Mitigation only Fix from $2,3002016-02-16