CVE-2025-42958
- EPSS 0.09%
- Veröffentlicht 09.09.2025 02:15:42
- Zuletzt bearbeitet 09.09.2025 16:28:43
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functio...
CVE-2025-42999
- EPSS 21.54%
- Veröffentlicht 13.05.2025 00:17:43
- Zuletzt bearbeitet 16.05.2025 19:44:49
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31324
- EPSS 30.15%
- Veröffentlicht 24.04.2025 16:50:27
- Zuletzt bearbeitet 06.05.2025 20:59:33
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...
CVE-2025-31331
- EPSS 0.03%
- Veröffentlicht 08.04.2025 07:15:23
- Zuletzt bearbeitet 08.04.2025 18:13:53
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes...
CVE-2025-26661
- EPSS 0.09%
- Veröffentlicht 11.03.2025 01:15:35
- Zuletzt bearbeitet 11.03.2025 01:15:35
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly...
CVE-2024-33006
- EPSS 0.53%
- Veröffentlicht 14.05.2024 16:17:14
- Zuletzt bearbeitet 21.11.2024 09:16:13
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
CVE-2024-27898
- EPSS 0.22%
- Veröffentlicht 09.04.2024 01:15:48
- Zuletzt bearbeitet 06.02.2025 19:01:07
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the externa...
CVE-2024-25644
- EPSS 0.29%
- Veröffentlicht 12.03.2024 01:15:49
- Zuletzt bearbeitet 10.04.2025 19:40:55
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
CVE-2024-22124
- EPSS 0.05%
- Veröffentlicht 09.01.2024 02:15:46
- Zuletzt bearbeitet 21.11.2024 08:55:37
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53,...
CVE-2023-41367
- EPSS 0.19%
- Veröffentlicht 12.09.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:21:10
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under ...