Showing 2 vulnerabilities on this page for SAP NetWeaver AS Java (ServerCore)

Signals CISA KEV Ransomware Nuclei
SAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.

CWE-79Dec 11, 2018
CVSS6.1v3.1EPSS1.06%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).

CWE-862Dec 11, 2018
CVSS7.4v3.1EPSS0.552%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX