SAP SE / SAP Netweaver AS Java
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-47582 | XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA | MEDIUM | 5.3 | Dec 10, 2024 |
| CVE-2024-28164 | Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures) | MEDIUM | 5.3 | Jun 11, 2024 |
| CVE-2024-34688 | Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository) | HIGH | 7.5 | Jun 11, 2024 |
| CVE-2023-42477 | Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application) | MEDIUM | 6.5 | Oct 10, 2023 |
| CVE-2020-26826 | Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without pr… | MEDIUM | 6.5 | Dec 9, 2020 |
| CVE-2020-26820 | SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, t… | HIGH | 7.2 | Nov 10, 2020 |
| CVE-2020-6263 | Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CO… | CRITICAL | 9.8 | Jun 10, 2020 |
| CVE-2019-0391 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise… | MEDIUM | 4.3 | Nov 13, 2019 |
| CVE-2018-2452 | The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a c… | MEDIUM | 6.1 | Sep 11, 2018 |
Showing 1 to 5 of 5 CVEs