CVE-2025-42958
- EPSS 0.09%
- Published 09.09.2025 02:15:42
- Last modified 09.09.2025 16:28:43
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functio...
CVE-2025-42999
- EPSS 21.54%
- Published 13.05.2025 00:17:43
- Last modified 16.05.2025 19:44:49
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31324
- EPSS 30.15%
- Published 24.04.2025 16:50:27
- Last modified 06.05.2025 20:59:33
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...
CVE-2025-31331
- EPSS 0.03%
- Published 08.04.2025 07:15:23
- Last modified 08.04.2025 18:13:53
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes...
CVE-2025-26661
- EPSS 0.09%
- Published 11.03.2025 01:15:35
- Last modified 11.03.2025 01:15:35
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly...
CVE-2024-33006
- EPSS 0.53%
- Published 14.05.2024 16:17:14
- Last modified 21.11.2024 09:16:13
An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.
CVE-2024-27898
- EPSS 0.22%
- Published 09.04.2024 01:15:48
- Last modified 06.02.2025 19:01:07
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the externa...
CVE-2024-25644
- EPSS 0.29%
- Published 12.03.2024 01:15:49
- Last modified 10.04.2025 19:40:55
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
CVE-2024-22124
- EPSS 0.05%
- Published 09.01.2024 02:15:46
- Last modified 21.11.2024 08:55:37
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53,...
CVE-2023-41367
- EPSS 0.19%
- Published 12.09.2023 02:15:12
- Last modified 21.11.2024 08:21:10
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under ...