SAP
SAP Netweaver Enterprise Portal: vulnerabilidades y CVE
SAP Netweaver Enterprise Portal tiene 29 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses5
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44759 | Media (6.1) | 0.29% | — | 14 jul 2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL… |
| CVE-2026-27685 | Crítica (9.1) | 0.57% | — | 10 mar 2026 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and… |
| CVE-2026-0499 | Media (6.1) | 0.20% | — | 13 ene 2026 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL… |
| CVE-2025-42872 | Media (6.1) | 0.26% | — | 9 dic 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the… |
| CVE-2025-42884 | Media (6.5) | 0.26% | — | 11 nov 2025 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could… |
| CVE-2025-42980 | Crítica (9.1) | 0.76% | — | 8 jul 2025 | SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of… |
| CVE-2025-42964 | Crítica (9.1) | 0.72% | — | 8 jul 2025 | SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality,… |
| CVE-2025-23194 | Media (5.3) | 0.32% | — | 11 mar 2025 | SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on… |
| CVE-2024-47594 | Media (5.4) | 0.26% | — | 8 oct 2024 | SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into… |
| CVE-2024-44120 | Media (4.7) | 0.25% | — | 10 sept 2024 | SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click… |
| CVE-2024-25645 | Media (5.3) | 0.41% | — | 12 mar 2024 | Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no… |
| CVE-2023-28761 | Media (6.5) | 0.38% | — | 11 abr 2023 | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings… |
| CVE-2023-26461 | Media (4.9) | 0.52% | — | 14 mar 2023 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to… |
| CVE-2022-35298 | Media (6.1) | 0.54% | — | 13 sept 2022 | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of… |
| CVE-2022-35227 | Media (6.1) | 0.73% | — | 12 jul 2022 | A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful… |
| CVE-2022-35225 | Media (6.1) | 0.61% | — | 12 jul 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,… |
| CVE-2022-35172 | Media (6.1) | 0.61% | — | 12 jul 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |
| CVE-2022-35170 | Media (6.1) | 0.61% | — | 12 jul 2022 | SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,… |
| CVE-2022-32247 | Media (6.1) | 0.85% | — | 12 jul 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while… |
| CVE-2022-26105 | Media (6.1) | 0.91% | — | 12 abr 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while… |
| CVE-2022-24397 | Media (6.1) | 0.83% | — | 10 mar 2022 | SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting… |
| CVE-2022-24395 | Media (6.1) | 0.61% | — | 10 mar 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |
| CVE-2021-21489 | Media (4.8) | 0.57% | — | 14 sept 2021 | SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an… |
| CVE-2021-33703 | Media (6.1) | 1.5% | — | 10 ago 2021 | Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack… |
| CVE-2021-33702 | Media (6.1) | 1.5% | — | 10 ago 2021 | Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a… |
| CVE-2020-6323 | Media (6.1) | 0.65% | — | 15 oct 2020 | SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both… |
| CVE-2018-2435 | Media (6.1) | 1.3% | — | 10 jul 2018 | SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
| CVE-2015-2812 | Media (5) | 2.5% | — | 1 abr 2015 | XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966. |
| CVE-2015-2811 | Media (5) | 2.4% | — | 1 abr 2015 | XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Internet Graphics Server · 28