SAP

Netweaver

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Veröffentlicht 14.03.2023 05:15:28
  • Zuletzt bearbeitet 21.11.2024 07:36:24

Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site sc...

  • EPSS 0.72%
  • Veröffentlicht 13.06.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 06:56:58

Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks t...

  • EPSS 1.42%
  • Veröffentlicht 12.04.2022 17:15:10
  • Zuletzt bearbeitet 21.11.2024 06:57:54

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, ...

  • EPSS 1.46%
  • Veröffentlicht 12.04.2022 17:15:10
  • Zuletzt bearbeitet 25.02.2026 15:16:58

Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.

  • EPSS 0.84%
  • Veröffentlicht 09.02.2022 23:15:18
  • Zuletzt bearbeitet 21.11.2024 06:46:58

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation ca...

  • EPSS 0.75%
  • Veröffentlicht 12.10.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:16:35

SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim an...

Warnung
  • EPSS 36.02%
  • Veröffentlicht 14.09.2021 12:15:10
  • Zuletzt bearbeitet 25.02.2026 13:46:59

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running o...

  • EPSS 0.5%
  • Veröffentlicht 09.03.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:48:27

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant admi...

  • EPSS 1.11%
  • Veröffentlicht 14.07.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:26

SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

  • EPSS 1.86%
  • Veröffentlicht 10.03.2020 21:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:17

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory...