Showing 2 vulnerabilities on this page for netweaver_application_server_java

Signals CISA KEV Ransomware Nuclei
SAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.

CWE-307Nov 12, 2024
CVSS5.3v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP netweaver_application_server_java Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.

CWE-22Jul 14, 2020
CVSS5.3v3.1EPSS28.3%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX