VendorsSAPnetweaver_application_server_for_java7.50
Vulnerabilities

SAP NetWeaver Application Server for Java 7.50

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-23857
Improper Access Control in SAP NetWeaver AS for Java
Published 2023-03-14 · Modified
9.9EPSS 0.005
CVE-2023-0017
Improper access control in SAP NetWeaver AS for Java
Published 2023-01-10 · Modified
9.8EPSS 0.157
CVE-2023-30744
Improper access control during application start-up in SAP AS NetWeaver JAVA.
Published 2023-05-09 · Modified
9.1EPSS 0.006
CVE-2021-27635
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
Published 2021-06-09 · Modified
9.0EPSS 0.016
CVE-2022-27669
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
Published 2022-04-12 · Modified
7.5EPSS 0.010
CVE-2021-27621
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.
Published 2021-06-09 · Modified
5.5EPSS 0.006
CVE-2023-26460
Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)
Published 2023-03-14 · Modified
5.3EPSS 0.005
CVE-2023-31405
Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)
Published 2023-07-11 · Modified
5.3EPSS 0.004
CVE-2023-27268
Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)
Published 2023-03-14 · Modified
5.3EPSS 0.004