« Back to list

SAP

SAP Netweaver: vulnerabilities and CVEs

SAP Netweaver has 119 published vulnerabilities, 7 of them in the last 12 months. 12 are rated critical and 3 are listed by CISA as actively exploited.

CVEs119
Last 12 months7
Critical12
Actively exploited3

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-42999Critical (9.1)14%⚠ Active exploitationMay 13, 2025
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality,…
CVE-2025-31324Critical (9.8)99%⚠ Active exploitationApr 24, 2025
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system.…
CVE-2021-38163High (8.8)36%⚠ Active exploitationSep 14, 2021
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76963Medium (4.3)0.28%—Sep 8, 2026
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful…
CVE-2026-58241Medium (4.2)0.25%—Aug 11, 2026
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific…
CVE-2026-27671Critical (9.8)0.62%—Jun 9, 2026
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors…
CVE-2026-40129Medium (4.3)0.34%—May 12, 2026
Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the…
CVE-2026-27684Medium (6.4)0.33%—Mar 10, 2026
SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates…
CVE-2026-23685Medium (4.4)0.13%—Feb 10, 2026
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the…
CVE-2025-42874High (7.9)0.47%—Dec 9, 2025
SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote…
CVE-2025-42958Critical (9.1)0.69%—Sep 9, 2025
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access…
CVE-2025-42944Critical (10)2.9%—Sep 9, 2025
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such…
CVE-2025-42968Medium (4.3)0.26%—Jul 8, 2025
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific…
CVE-2025-42966Critical (9.1)0.72%—Jul 8, 2025
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object.…
CVE-2025-42953High (8.1)0.47%—Jul 8, 2025
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with…
CVE-2025-31325Medium (5.8)0.31%—Jun 10, 2025
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim…
CVE-2025-42999Critical (9.1)14%⚠ Active exploitationMay 13, 2025
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality,…
CVE-2025-31329Medium (6.2)0.34%—May 13, 2025
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these…
CVE-2025-31324Critical (9.8)99%⚠ Active exploitationApr 24, 2025
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system.…
CVE-2025-31331Medium (4.3)0.35%—Apr 8, 2025
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a…
CVE-2025-30015Medium (4.1)0.26%—Apr 8, 2025
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to…
CVE-2025-26661High (8.8)0.42%—Mar 11, 2025
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could…
CVE-2024-44115Medium (4.3)0.25%—Sep 10, 2024
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's…
CVE-2024-30218Medium (6.5)0.53%—Apr 9, 2024
The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable…
CVE-2024-27898Medium (5.3)0.45%—Apr 9, 2024
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible…
CVE-2024-25644Medium (5.3)0.41%—Mar 12, 2024
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and…
CVE-2024-22124High (7.5)0.33%—Jan 9, 2024
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT,…
CVE-2023-41367Medium (5.3)0.55%—Sep 12, 2023
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful…
CVE-2023-36922High (8.8)0.84%—Jul 11, 2023
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a…
CVE-2023-33985Medium (6.1)0.51%—Jun 13, 2023
SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the…
CVE-2023-33984Medium (5.4)0.40%—Jun 13, 2023
SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to…
CVE-2023-32114Low (2.7)0.60%—Jun 13, 2023
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in…
CVE-2023-29186Medium (6.5)23%—Apr 11, 2023
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1059.004 Unix Shell1
  3. T1059.007 JavaScript1
  4. T1190 Exploit Public-Facing Application1
  5. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by SAP