SAP

Netweaver

104 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in the (1) JavaDumpService and (2) DataCollector servlets in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.25%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Performance Provider in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.72%
  • Published 24.10.2013 00:55:02
  • Last modified 11.04.2025 00:51:21

The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in ...

  • EPSS 0.43%
  • Published 16.09.2013 19:14:40
  • Last modified 11.04.2025 00:51:21

Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.

  • EPSS 0.79%
  • Published 12.09.2013 13:31:15
  • Last modified 11.04.2025 00:51:21

SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."

  • EPSS 11.7%
  • Published 16.08.2013 17:55:05
  • Last modified 11.04.2025 00:51:21

The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.

Exploit
  • EPSS 0.29%
  • Published 12.02.2013 20:55:03
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via the page parameter.

Exploit
  • EPSS 0.48%
  • Published 12.02.2013 20:55:03
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the server parameter.

Exploit
  • EPSS 16.25%
  • Published 15.05.2012 04:21:43
  • Last modified 11.04.2025 00:51:21

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

Exploit
  • EPSS 22.65%
  • Published 15.05.2012 04:21:43
  • Last modified 11.04.2025 00:51:21

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.