VendorsSAPnetweaver701
Vulnerabilities

SAP Netweaver 7.0 (aka 2004s) 701

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-22534
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
Published 2022-02-09 · Modified
6.1EPSS 0.008
CVE-2021-38183
SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
Published 2021-10-12 · Modified
6.1EPSS 0.007
CVE-2023-0021
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Published 2023-03-14 · Modified
6.1EPSS 0.005
CVE-2025-42968
Missing Authorization check in SAP NetWeaver (RFC enabled function module)
Published 2025-07-08 · Analyzed
5.0EPSS 0.002