VendorsSAPnetweaver750
Vulnerabilities

SAP Netweaver 7.0 (aka 2004s) 750

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-22534
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
Published 2022-02-09 · Modified
6.1EPSS 0.008
CVE-2023-0021
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Published 2023-03-14 · Modified
6.1EPSS 0.005
CVE-2025-42968
Missing Authorization check in SAP NetWeaver (RFC enabled function module)
Published 2025-07-08 · Analyzed
5.0EPSS 0.002
CVE-2023-32114
Denial of Service in SAP NetWeaver
Published 2023-06-13 · Modified
2.7EPSS 0.006