Show filters
84 Total Results
Displaying 21-30 of 84
Sort by:
Attacker Value
Unknown
CVE-2022-41262
Disclosure Date: December 12, 2022 (last updated November 08, 2023)
Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2022-27669
Disclosure Date: April 12, 2022 (last updated October 07, 2023)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
0
Attacker Value
Unknown
CVE-2022-26103
Disclosure Date: March 10, 2022 (last updated October 07, 2023)
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
0
Attacker Value
Unknown
CVE-2022-22532
Disclosure Date: February 09, 2022 (last updated October 07, 2023)
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be executed and hence execute functions that could be impersonating the victim or even steal the victim's logon session.
0
Attacker Value
Unknown
CVE-2022-22533
Disclosure Date: February 09, 2022 (last updated November 29, 2024)
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system unavailable.
0
Attacker Value
Unknown
CVE-2021-37535
Disclosure Date: September 14, 2021 (last updated February 23, 2025)
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
0
Attacker Value
Unknown
CVE-2021-33670
Disclosure Date: July 14, 2021 (last updated November 28, 2024)
SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple HTTP requests with different method types thereby crashing the filter and making the HTTP server unavailable to other legitimate users leading to denial of service vulnerability.
0
Attacker Value
Unknown
CVE-2021-33689
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
0
Attacker Value
Unknown
CVE-2021-33687
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS to steal this information.
0
Attacker Value
Unknown
CVE-2021-27621
Disclosure Date: June 09, 2021 (last updated November 28, 2024)
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.
0