VendorsSAPnetweaverall versions
Vulnerabilities

SAP Netweaver 7.0 (aka 2004s)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

104CVEs
CVE-2015-2107
HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.
Published 2015-03-14 · Modified
6.8EPSS 0.003
CVE-2015-2815
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369.
Published 2015-04-01 · Modified
6.5EPSS 0.037
CVE-2014-6252
Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated users to cause a denial of service or execute arbitrary code via unspecified vectors.
Published 2014-09-05 · Modified
6.5EPSS 0.024
CVE-2022-28217
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
Published 2022-06-13 · Modified
6.5EPSS 0.007
CVE-2013-6823
GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.
Published 2013-11-19 · Modified
6.4EPSS 0.012
CVE-2023-33984
Cross-Site Scripting (XSS) vulnerability in NetWeaver (Design Time Repository)
Published 2023-06-13 · Modified
6.4EPSS 0.004
CVE-2016-2387
Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or (2) interface parameter to ProxyServer/register, aka SAP Security Note 2220571.
Published 2016-02-16 · Modified
6.1EPSS 0.015
CVE-2018-2470
In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Published 2018-10-09 · Modified
6.1EPSS 0.013
CVE-2018-2464
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
Published 2018-09-11 · Modified
6.1EPSS 0.013
CVE-2016-1911
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest servlet in the Process Monitoring Infrastructure (PMI), aka SAP Security Notes 2206793 and 2234918.
Published 2016-01-15 · Modified
6.1EPSS 0.010
CVE-2020-6184
Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
Published 2020-02-12 · Modified
6.1EPSS 0.010
CVE-2018-2476
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
Published 2018-11-13 · Modified
6.1EPSS 0.010
CVE-2022-22534
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
Published 2022-02-09 · Modified
6.1EPSS 0.008
CVE-2021-38183
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
Published 2021-10-12 · Modified
6.1EPSS 0.007
CVE-2023-33985
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Published 2023-06-13 · Modified
6.1EPSS 0.005
CVE-2023-0021
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Published 2023-03-14 · Modified
6.1EPSS 0.005
CVE-2023-27499
Cross-Site Scripting (XSS) vulnerability in SAP GUI for HTML
Published 2023-04-11 · Modified
6.1EPSS 0.004
CVE-2019-0248
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.
Published 2019-01-08 · Modified
5.9EPSS 0.016
CVE-2013-6814
The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
Published 2013-11-19 · Modified
5.8EPSS 0.018
CVE-2020-6181
Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
Published 2020-02-12 · Modified
5.8EPSS 0.008
CVE-2020-6185
Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
Published 2020-02-12 · Modified
5.4EPSS 0.005
CVE-2016-1910
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
Published 2016-01-15 · Modified
5.31 PoCEPSS 0.065
CVE-2023-41367
Missing Authentication check in SAP NetWeaver (Guided Procedures)
Published 2023-09-12 · Modified
5.3EPSS 0.005
CVE-2024-27898
Server-Side Request Forgery in SAP NetWeaver
Published 2024-04-09 · Analyzed
5.3EPSS 0.004
CVE-2024-25644
Information Disclosure vulnerability in NetWeaver (WSRM)
Published 2024-03-12 · Analyzed
5.3EPSS 0.004
CVE-2013-3319
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
Published 2013-08-16 · Modified
5.0EPSS 0.203
CVE-2014-0995
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern.
Published 2014-11-06 · Modified
5.01 PoCEPSS 0.105
CVE-2012-2511
The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Published 2012-05-15 · Modified
5.02 PoCEPSS 0.040
CVE-2012-2512
The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Published 2012-05-15 · Modified
5.02 PoCEPSS 0.036
CVE-2012-2513
The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Published 2012-05-15 · Modified
5.02 PoCEPSS 0.036
CVE-2012-2514
The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Published 2012-05-15 · Modified
5.02 PoCEPSS 0.036
CVE-2012-2612
The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.
Published 2012-05-15 · Modified
5.02 PoCEPSS 0.036
CVE-2015-2817
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.
Published 2015-04-01 · Modified
5.0EPSS 0.024
CVE-2014-8592
Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via a crafted request.
Published 2014-11-04 · Modified
5.0EPSS 0.021
CVE-2014-1961
Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.
Published 2014-02-14 · Modified
5.0EPSS 0.021
CVE-2013-5751
Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.
Published 2013-09-16 · Modified
5.0EPSS 0.021
CVE-2014-8591
Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via unknown vectors.
Published 2014-11-04 · Modified
5.0EPSS 0.019
CVE-2013-6821
Directory traversal vulnerability in the Exportability Check Service in SAP NetWeaver allows remote attackers to read arbitrary files via unspecified vectors.
Published 2013-11-19 · Modified
5.0EPSS 0.019
CVE-2013-6815
The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denial of service via unspecified vectors, related to an XML External Entity (XXE) issue.
Published 2013-11-19 · Modified
5.0EPSS 0.017
CVE-2013-6244
The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Published 2013-10-24 · Modified
5.0EPSS 0.016
← Prev2 / 3Next →