SAP

Netweaver Application Server Java

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.04.2021 19:15:15
  • Zuletzt bearbeitet 21.11.2024 05:58:16

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

  • EPSS 0.16%
  • Veröffentlicht 13.04.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:48:28

SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.

  • EPSS 0.27%
  • Veröffentlicht 13.04.2021 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:48:28

An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.

  • EPSS 0.13%
  • Veröffentlicht 10.03.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:48:28

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

  • EPSS 3.95%
  • Veröffentlicht 09.12.2020 17:15:31
  • Zuletzt bearbeitet 21.11.2024 05:20:21

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment d...

  • EPSS 0.45%
  • Veröffentlicht 09.12.2020 17:15:30
  • Zuletzt bearbeitet 21.11.2024 05:20:21

Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.

  • EPSS 0.02%
  • Veröffentlicht 09.12.2020 17:15:30
  • Zuletzt bearbeitet 21.11.2024 05:20:20

SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This ...

  • EPSS 3.16%
  • Veröffentlicht 10.11.2020 17:15:14
  • Zuletzt bearbeitet 21.11.2024 05:20:20

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacke...

  • EPSS 0.21%
  • Veröffentlicht 15.10.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:35

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute p...

  • EPSS 0.32%
  • Veröffentlicht 15.10.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:30

SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successfu...