« Back to list

SAP

SAP Netweaver Application Server FOR Java: vulnerabilities and CVEs

SAP Netweaver Application Server FOR Java has 10 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months0
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-42963Critical (9.1)0.74%—Jul 8, 2025
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full…
CVE-2023-31405Medium (5.3)0.45%—Jul 11, 2023
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log…
CVE-2023-30744Critical (9.1)0.62%—May 9, 2023
In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object…
CVE-2023-27268Medium (5.3)0.45%—Mar 14, 2023
SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and…
CVE-2023-26460Medium (5.3)0.48%—Mar 14, 2023
Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
CVE-2023-23857High (8.6)0.54%—Mar 14, 2023
Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which…
CVE-2023-0017Critical (9.8)16%—Jan 10, 2023
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be…
CVE-2022-27669High (7.5)1.0%—Apr 12, 2022
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
CVE-2021-27635Medium (6.5)1.6%—Jun 9, 2021
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of…
CVE-2021-27621Medium (4.9)0.61%—Jun 9, 2021
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering…

Other products by SAP