CVE-2025-27431
- EPSS 0.03%
- Published 11.03.2025 01:15:36
- Last modified 11.03.2025 01:15:36
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality,...
CVE-2025-24869
- EPSS 0.05%
- Published 11.02.2025 01:15:11
- Last modified 18.02.2025 18:15:33
SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, ...
CVE-2025-0054
- EPSS 0.04%
- Published 11.02.2025 01:15:09
- Last modified 18.02.2025 18:15:28
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which co...
CVE-2025-0067
- EPSS 0.08%
- Published 14.01.2025 01:15:16
- Last modified 14.01.2025 01:15:16
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server....
CVE-2024-47592
- EPSS 0.13%
- Published 12.11.2024 01:15:05
- Last modified 12.11.2024 13:55:21
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
CVE-2015-4091
- EPSS 0.96%
- Published 26.05.2015 14:59:00
- Last modified 12.04.2025 10:46:40
XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SA...