SAP_SE Vulnerabilities and Affected Products
Vulnerabilities associated with SAP NetWeaver Application Server Java.
Products
Clear product- SAP BusinessObjects Business Intelligence Platform22 vulnerabilities
- SAP NetWeaver Application Server for ABAP and ABAP Platform16 vulnerabilities
- SAP NetWeaver Application Server ABAP12 vulnerabilities
- SAP NetWeaver Application Server for ABAP12 vulnerabilities
- SAP Business AI Platform (Approuter)11 vulnerabilities
- SAP NetWeaver Application Server ABAP and ABAP Platform10 vulnerabilities
- SAP NetWeaver AS ABAP and ABAP Platform9 vulnerabilities
- SAP Commerce Cloud8 vulnerabilities
- SAP GUI for Windows8 vulnerabilities
- SAP NetWeaver Application Server Java8 vulnerabilities
- SAP Business Connector7 vulnerabilities
- SAP CRM WebClient UI7 vulnerabilities
- SAP Enable Now6 vulnerabilities
- SAP Fiori App (Intercompany Balance Reconciliation)6 vulnerabilities
- SAP NetWeaver Enterprise Portal6 vulnerabilities
- SAP Manufacturing Integration and Intelligence5 vulnerabilities
- SAP Supplier Relationship Management (Live Auction Cockpit)5 vulnerabilities
- SAP Web Dispatcher5 vulnerabilities
- SAP Commerce4 vulnerabilities
- SAP Financial Consolidation4 vulnerabilities
- SAP Host Agent4 vulnerabilities
- SAP NetWeaver4 vulnerabilities
- SAP NetWeaver AS Java4 vulnerabilities
- SAP Solution Manager4 vulnerabilities
- SAPCAR4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CRLF Injection vulnerability in SAP NetWeaver Application Server JavaDue to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected. | CVSS3.4v3.1 | EPSS0.164% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-42919MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server JavaDue to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive application metadata. This results in a partial compromise of the confidentiality of the information without affecting the integrity or availability of the application server. CWE-22Nov 11, 2025 | CVSS5.3v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-42926MEDIUM | Missing Authentication check in SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This vulnerability has a low impact on confidentiality and does not affect the integrity or availability of the server. CWE-306Sep 9, 2025 | CVSS5.3v3.1 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Application Server JavaThe widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being established to a possibly malicious remote TLS server and hence disclose information. Integrity and Availability are not impacted. CWE-940Jul 8, 2025 | CVSS3.5v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-27431MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server JavaUser management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data modifications within the scope of victim�s browser. There is no impact on availability. CWE-79Mar 11, 2025 | CVSS5.4v3.1 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24869MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be exposed without compromising its integrity or availability. CWE-863Feb 11, 2025 | CVSS4.3v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0054MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page. CWE-79Feb 11, 2025 | CVSS5.4v3.1 | EPSS0.264% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0067MEDIUM | Missing Authorization check in SAP NetWeaver Application Server JavaDue to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and availability of the application. CWE-862Jan 14, 2025 | CVSS6.3v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |