Showing 19 vulnerabilities on this page for NetWeaver

Signals CISA KEV Ransomware Nuclei
SAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Insecure Deserialization in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

CWE-502May 13, 2025
CVSS9.1v3.1EPSS11.3%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Missing Authorization check in SAP NetWeaver (Visual Composer development server)

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CWE-434Apr 24, 20251 related artifact
CVSS10.0v3.1EPSS99.5%PoCs20SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.

CWE-200Jun 11, 2024
CVSS5.3v3.1EPSS0.326%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)

Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.

CWE-400Jun 11, 2024
CVSS7.5v3.1EPSS0.541%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

File upload vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.

CWE-434May 14, 2024
CVSS9.6v3.1EPSS0.527%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Server-Side Request Forgery in SAP NetWeaver

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.

CWE-918Apr 9, 2024
CVSS5.3v3.1EPSS0.445%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Information Disclosure vulnerability in NetWeaver (WSRM)

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

CWE-200CWE-732Mar 12, 2024
CVSS5.3v3.1EPSS0.41%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

CWE-77CWE-94Mar 12, 2024
CVSS9.1v3.1EPSS1.59%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50The SAP NetWeaver Development Infrastructure Component Build Service allows a threat actor who has access to the server to perform proxy attacks on server by sending crafted queries. Due to this, the threat actor could completely compromise sensitive data residing on the Server and impact its availability.Note: The

CWE-918Sep 15, 20211 related artifact
CVSS9.9v3.1EPSS67.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS9.9v3.1EPSS36%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CWE-287CWE-306Jul 14, 20201 related artifact
CVSS10.0v3.1EPSS94.7%PoCs8SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SAP NetWeaver Directory Traversal Vulnerability

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

CWE-22Aug 7, 20171 related artifact
CVSS7.5v3.1EPSS95.1%PoCs1SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SAP NetWeaver Deserialization of Untrusted Data

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service.

CWE-502Jul 12, 2017
CVSS7.5v3.1EPSS5.51%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver XML External Entity (XXE) Vulnerability

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

CWE-611Nov 23, 2016
CVSS6.5v3.1EPSS23.8%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver Remote Code Execution Vulnerability

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

CWE-306May 13, 2016
CVSS10.0v3.1EPSS17.5%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver Directory Traversal Vulnerability

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

CWE-22Apr 7, 2016
CVSS7.5v3.1EPSS46.6%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

CWE-22Feb 16, 20161 related artifact
CVSS7.5v3.0EPSS41.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SAP NetWeaver Information Disclosure Vulnerability

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

CWE-200Feb 16, 2016
CVSS5.3v3.1EPSS51.6%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

CWE-89Feb 16, 2016
CVSS9.8v3.1EPSS71.1%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX