VendorsSAPnetweaver7.50
Vulnerabilities

SAP Netweaver 7.0 (aka 2004s) 7.50

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Published 2025-04-24 · Analyzed
10.0KEVEPSS 0.995
CVE-2021-38163
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
Published 2021-09-14 · Analyzed
9.9KEVEPSS 0.360
CVE-2021-21481
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, and availability.
Published 2021-03-09 · Modified
9.6EPSS 0.005
CVE-2020-6203
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
Published 2020-03-10 · Modified
9.1EPSS 0.019
CVE-2019-0351
A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Because of this, an attacker can exploit Services Registry potentially enabling them to take complete control of the product, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.
Published 2019-08-14 · Modified
8.8EPSS 0.025
CVE-2018-2477
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
Published 2018-11-13 · Modified
8.8EPSS 0.017
CVE-2018-2462
In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.
Published 2018-09-11 · Modified
8.8EPSS 0.016
CVE-2020-6285
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Published 2020-07-14 · Modified
7.7EPSS 0.011
CVE-2022-28217
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
Published 2022-06-13 · Modified
6.5EPSS 0.007
CVE-2023-33984
Cross-Site Scripting (XSS) vulnerability in NetWeaver (Design Time Repository)
Published 2023-06-13 · Modified
6.4EPSS 0.004
CVE-2018-2464
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
Published 2018-09-11 · Modified
6.1EPSS 0.013
CVE-2023-33985
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Published 2023-06-13 · Modified
6.1EPSS 0.005
CVE-2023-41367
Missing Authentication check in SAP NetWeaver (Guided Procedures)
Published 2023-09-12 · Modified
5.3EPSS 0.005
CVE-2024-25644
Information Disclosure vulnerability in NetWeaver (WSRM)
Published 2024-03-12 · Analyzed
5.3EPSS 0.004
CVE-2026-23685
Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
Published 2026-02-10 · Analyzed
4.4EPSS 0.001