VendorsSAPnetweaver7.5
Vulnerabilities

SAP Netweaver 7.0 (aka 2004s) 7.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2016-10311
Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.
Published 2017-04-10 · Modified
9.8EPSS 0.022
CVE-2025-42999
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
Published 2025-05-13 · Analyzed
9.1KEVEPSS 0.139
CVE-2019-0248
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted.
Published 2019-01-08 · Modified
5.9EPSS 0.016
CVE-2024-27898
Server-Side Request Forgery in SAP NetWeaver
Published 2024-04-09 · Analyzed
5.3EPSS 0.004