SAP

Netweaver

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 12.03.2024 01:15:49
  • Zuletzt bearbeitet 10.04.2025 19:40:55

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

  • EPSS 0.05%
  • Veröffentlicht 09.01.2024 02:15:46
  • Zuletzt bearbeitet 21.11.2024 08:55:37

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53,...

  • EPSS 0.19%
  • Veröffentlicht 12.09.2023 02:15:12
  • Zuletzt bearbeitet 21.11.2024 08:21:10

Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under ...

  • EPSS 0.17%
  • Veröffentlicht 11.07.2023 03:15:10
  • Zuletzt bearbeitet 21.11.2024 08:10:55

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On su...

  • EPSS 0.08%
  • Veröffentlicht 13.06.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:02:44

SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the serve...

  • EPSS 0.54%
  • Veröffentlicht 13.06.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:20

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant...

  • EPSS 0.5%
  • Veröffentlicht 13.06.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:21

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitat...

  • EPSS 28.49%
  • Veröffentlicht 11.04.2023 04:16:08
  • Zuletzt bearbeitet 21.11.2024 07:56:40

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrativ...

  • EPSS 0.53%
  • Veröffentlicht 11.04.2023 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:53:01

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability....

  • EPSS 2.04%
  • Veröffentlicht 14.03.2023 05:15:28
  • Zuletzt bearbeitet 21.11.2024 07:36:24

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site sc...