SAP

Netweaver

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.04%
  • Veröffentlicht 11.11.2025 00:13:47
  • Zuletzt bearbeitet 12.11.2025 16:19:59

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a mali...

Medienbericht
  • EPSS 0.1%
  • Veröffentlicht 09.09.2025 02:15:42
  • Zuletzt bearbeitet 09.09.2025 16:28:43

Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functio...

  • EPSS 0.03%
  • Veröffentlicht 08.07.2025 00:36:31
  • Zuletzt bearbeitet 27.10.2025 16:57:45

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditi...

Warnung Medienbericht Exploit
  • EPSS 31.52%
  • Veröffentlicht 13.05.2025 00:17:43
  • Zuletzt bearbeitet 31.10.2025 21:58:56

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...

Warnung Medienbericht
  • EPSS 45.8%
  • Veröffentlicht 24.04.2025 16:50:27
  • Zuletzt bearbeitet 31.10.2025 21:56:14

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...

  • EPSS 0.04%
  • Veröffentlicht 08.04.2025 07:15:23
  • Zuletzt bearbeitet 08.04.2025 18:13:53

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes...

  • EPSS 0.13%
  • Veröffentlicht 11.03.2025 01:15:35
  • Zuletzt bearbeitet 11.03.2025 01:15:35

Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly...

  • EPSS 0.53%
  • Veröffentlicht 14.05.2024 16:17:14
  • Zuletzt bearbeitet 21.11.2024 09:16:13

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. 

  • EPSS 0.22%
  • Veröffentlicht 09.04.2024 01:15:48
  • Zuletzt bearbeitet 06.02.2025 19:01:07

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the externa...

  • EPSS 0.29%
  • Veröffentlicht 12.03.2024 01:15:49
  • Zuletzt bearbeitet 10.04.2025 19:40:55

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.