target entity

NetWeaver

10 source-linked records in the current knowledge graph.

high

CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-42999EPSS 12.5%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31324: SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31324EPSS 99.4%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12637: SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2017-12637EPSS 94.6%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2016-2386: SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Required action: Apply updates per vendor instructions.

CVE-2016-2386EPSS 71.1%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. Required action: Apply updates per vendor instructions.

CVE-2016-9563EPSS 23.8%NetWeaverSAP
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3976: SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. Required action: Apply updates per vendor instructions.

CVE-2016-3976EPSS 46.6%NetWeaverSAP
CISA KEV ↗ · unattributed attribution