Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver CRITICAL 9.1
CVE-2025-42999 KEVEPSS 12%

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ…

Mitigation only
Fix from $2,300 2025-05-13
Netweaver CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…

Mitigation only
Fix from $2,300 2025-04-24
Content Server CRITICAL 10.0
CVE-2022-22536 KEVEPSS 98%

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne…

Mitigation only
Fix from $2,300 2022-02-09
Netweaver HIGH 8.8
CVE-2021-38163 KEVEPSS 36%

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user…

Mitigation only
Fix from $1,950 2021-09-14
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…

Mitigation only
Fix from $2,300 2020-07-14
Solution Manager CRITICAL 9.8
CVE-2020-6207 KEVEPSS 98%

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic…

Mitigation only
Fix from $2,300 2020-03-10
Commerce Cloud CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…

Mitigation only
Fix from $2,300 2019-08-14
Customer Relationship Management MEDIUM 6.6
CVE-2018-2380 KEVEPSS 29%

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus charact…

Mitigation only
Fix from $1,600 2018-03-01
Netweaver Application Server Java HIGH 7.5
CVE-2017-12637 KEVEPSS 95%

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…

Mitigation only
Fix from $1,950 2017-08-07
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…

Mitigation only
Fix from $1,600 2016-11-23
Netweaver Application Server Java CRITICAL 10.0
CVE-2010-5326 KEVEPSS 17%

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att…

Fix: after 7.30
Fix from $2,300 2016-05-13
Netweaver Application Server Java HIGH 7.5
CVE-2016-3976 KEVEPSS 47%

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backsla…

Fix: after 7.50
Fix from $1,950 2016-04-07
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-2388 KEVEPSS 52%

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req…

Fix: after 7.50
Fix from $1,600 2016-02-16
Netweaver Application Server Java CRITICAL 9.8
CVE-2016-2386 KEVEPSS 71%

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspec…

Mitigation only
Fix from $2,300 2016-02-16