SAP Vulnerabilities and Affected Products
Vulnerabilities associated with NetWeaver.
Products
Clear product- NetWeaver19 vulnerabilities
- NetWeaver AS for ABAP and ABAP Platform7 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform5 vulnerabilities
- SAP Fiori Client5 vulnerabilities
- commerce_cloud4 vulnerabilities
- Solution Manager4 vulnerabilities
- BusinessObjects Business Intelligence Platform (Web Services)3 vulnerabilities
- NetWeaver Application Server for ABAP and ABAP Platform3 vulnerabilities
- NetWeaver AS ABAP (BSP Framework)3 vulnerabilities
- NetWeaver AS for Java3 vulnerabilities
- SAP BusinessObjects Business Intelligence3 vulnerabilities
- SAP HANA extended application services3 vulnerabilities
- SAP Internet Graphics Server (IGS)3 vulnerabilities
- Application Interface Framework (Message Dashboard)2 vulnerabilities
- Business Planning and Consolidation2 vulnerabilities
- business_objects_business_intelligence_platform2 vulnerabilities
- commerce_hycom2 vulnerabilities
- CRM (WebClient UI)2 vulnerabilities
- NetWeaver Process Integration2 vulnerabilities
- netweaver_application_server_java2 vulnerabilities
- SAP Adaptive Server Enterprise (ASE)2 vulnerabilities
- SAP BusinessObjects Business Intelligence Suite2 vulnerabilities
- SAP Enterprise Financial Services2 vulnerabilities
- SAP HANA2 vulnerabilities
- SAP NetWeaver AS Java (ServerCore)2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-42999CRITICAL | Insecure Deserialization in SAP NetWeaver (Visual Composer development server)SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. CWE-502May 13, 2025 | CVSS9.1v3.1 | EPSS11.3% | PoCs1 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2025-31324CRITICAL | Missing Authorization check in SAP NetWeaver (Visual Composer development server)SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | CVSS10.0v3.1 | EPSS99.5% | PoCs20 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2024-28164MEDIUM | Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application. CWE-200Jun 11, 2024 | CVSS5.3v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34688HIGH | Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application. CWE-400Jun 11, 2024 | CVSS7.5v3.1 | EPSS0.541% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33006CRITICAL | File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP PlatformAn unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. CWE-434May 14, 2024 | CVSS9.6v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-27898MEDIUM | Server-Side Request Forgery in SAP NetWeaverSAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality. CWE-918Apr 9, 2024 | CVSS5.3v3.1 | EPSS0.445% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-25644MEDIUM | Information Disclosure vulnerability in NetWeaver (WSRM)Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application. | CVSS5.3v3.1 | EPSS0.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22127CRITICAL | Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application. | CVSS9.1v3.1 | EPSS1.59% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33690CRITICAL | SAP NetWeaver Server-Side Request Forgery (SSRF)Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The… | CVSS9.9v3.1 | EPSS67.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-38163CRITICAL | SAP NetWeaver Unrestricted File Upload VulnerabilitySAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable. | CVSS9.9v3.1 | EPSS36% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-6287CRITICAL | SAP NetWeaver Missing Authentication for Critical Function VulnerabilitySAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check. | CVSS10.0v3.1 | EPSS94.7% | PoCs8 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-12637HIGH | SAP NetWeaver Directory Traversal VulnerabilityDirectory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657. | CVSS7.5v3.1 | EPSS95.1% | PoCs1 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-9844HIGH | SAP NetWeaver Deserialization of Untrusted DataSAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service. CWE-502Jul 12, 2017 | CVSS7.5v3.1 | EPSS5.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-9563MEDIUM | SAP NetWeaver XML External Entity (XXE) VulnerabilityBC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. CWE-611Nov 23, 2016 | CVSS6.5v3.1 | EPSS23.8% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2010-5326CRITICAL | SAP NetWeaver Remote Code Execution VulnerabilityThe Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack. CWE-306May 13, 2016 | CVSS10.0v3.1 | EPSS17.5% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-3976HIGH | SAP NetWeaver Directory Traversal VulnerabilityDirectory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971. CWE-22Apr 7, 2016 | CVSS7.5v3.1 | EPSS46.6% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-2389HIGH | SAP NetWeaver Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978. | CVSS7.5v3.0 | EPSS41.4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2016-2388MEDIUM | SAP NetWeaver Information Disclosure VulnerabilityThe Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846. CWE-200Feb 16, 2016 | CVSS5.3v3.1 | EPSS51.6% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-2386CRITICAL | SAP NetWeaver SQL Injection VulnerabilitySQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079. CWE-89Feb 16, 2016 | CVSS9.8v3.1 | EPSS71.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |