VendorsSAPcontent_serverall versions
Vulnerabilities

SAP Content Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-22536
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Published 2022-02-09 · Analyzed
10.0KEV1 PoCEPSS 0.979
CVE-2023-40309
Missing Authorization check in SAP CommonCryptoLib
Published 2023-09-12 · Modified
9.8EPSS 0.009
CVE-2023-40308
Memory Corruption vulnerability in SAP CommonCryptoLib
Published 2023-09-12 · Modified
7.5EPSS 0.008
CVE-2024-33005
Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server
Published 2024-08-13 · Analyzed
6.3EPSS 0.002
CVE-2023-26457
Cross-Site Scripting (XSS) vulnerability in SAP Content Server
Published 2023-03-14 · Modified
6.1EPSS 0.004
CVE-2015-4157
SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.
Published 2015-06-02 · Modified
5.0EPSS 0.013