SAP

Netweaver

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 11.09.2018 15:29:01
  • Zuletzt bearbeitet 21.11.2024 04:03:51

In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.

  • EPSS 0.13%
  • Veröffentlicht 10.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:03:48

A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovatio...

  • EPSS 0.74%
  • Veröffentlicht 09.01.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:03:40

SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the syst...

Exploit
  • EPSS 27.38%
  • Veröffentlicht 06.09.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

  • EPSS 1.86%
  • Veröffentlicht 12.07.2017 16:29:00
  • Zuletzt bearbeitet 02.05.2025 15:25:18

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that...

  • EPSS 4.19%
  • Veröffentlicht 12.07.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG request, aka SAP Security Note 2405918.

  • EPSS 6.79%
  • Veröffentlicht 10.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.

  • EPSS 0.71%
  • Veröffentlicht 23.01.2017 21:59:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) get...

  • EPSS 0.05%
  • Veröffentlicht 13.10.2016 14:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP Netweaver 7.40 improperly logs (1) DUI and (2) DUJ events in the SAP Security Audit Log as non-critical, which might allow local users to hide rejected attempts to execute RFC function callbacks by leveraging filtering of non-critical events in a...

  • EPSS 0.59%
  • Veröffentlicht 13.10.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RF...