SAP_SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP NetWeaver AS Java.
Products
Clear product- SAP BusinessObjects Business Intelligence Platform22 vulnerabilities
- SAP NetWeaver Application Server for ABAP and ABAP Platform16 vulnerabilities
- SAP NetWeaver Application Server ABAP12 vulnerabilities
- SAP NetWeaver Application Server for ABAP12 vulnerabilities
- SAP Business AI Platform (Approuter)11 vulnerabilities
- SAP NetWeaver Application Server ABAP and ABAP Platform10 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform9 vulnerabilities
- SAP Commerce Cloud8 vulnerabilities
- SAP GUI for Windows8 vulnerabilities
- SAP NetWeaver Application Server Java8 vulnerabilities
- SAP Business Connector7 vulnerabilities
- SAP CRM WebClient UI7 vulnerabilities
- SAP Enable Now6 vulnerabilities
- SAP Fiori App (Intercompany Balance Reconciliation)6 vulnerabilities
- SAP NetWeaver Enterprise Portal6 vulnerabilities
- SAP Manufacturing Integration and Intelligence5 vulnerabilities
- SAP Supplier Relationship Management (Live Auction Cockpit)5 vulnerabilities
- SAP Web Dispatcher5 vulnerabilities
- SAP Commerce4 vulnerabilities
- SAP Financial Consolidation4 vulnerabilities
- SAP Host Agent4 vulnerabilities
- SAP NetWeaver4 vulnerabilities
- SAP NetWeaver AS Java4 vulnerabilities
- SAP Solution Manager4 vulnerabilities
- SAPCAR4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-47582MEDIUM | XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVADue to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application. CWE-611Dec 10, 2024 | CVSS5.3v3.1 | EPSS0.424% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28164MEDIUM | Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application. CWE-200Jun 11, 2024 | CVSS5.3v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34688HIGH | Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application. CWE-400Jun 11, 2024 | CVSS7.5v3.1 | EPSS0.541% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42477MEDIUM | Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application. CWE-918Oct 10, 2023 | CVSS6.5v3.1 | EPSS0.414% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |