Netweaver Development Infrastructure
SAP SE · 4 CVEs
CVE-2022-29618
MEDIUM
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30…
Jun 14, 2022
CVE-2021-33691
MEDIUM
NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…
Sep 15, 2021
CVE-2021-33690
CRITICAL
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Comp…
Sep 15, 2021
CVE-2013-6820
HIGH
Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers t…
Nov 19, 2013
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-29618 | Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenti… | MEDIUM | 1.11% | Jun 14, 2022 |
| CVE-2021-33691 | NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabili… | MEDIUM | 0.64% | Sep 15, 2021 |
| CVE-2021-33690 | Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions - 7.11, 7.2… | CRITICAL | 69.08% | Sep 15, 2021 |
| CVE-2013-6820 | Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by uploading a… | HIGH | 3.59% | Nov 19, 2013 |
Showing 1 to 4 of 4 CVEs