Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Very High
CVE-2020-6287: Critical Vulnerability in SAP NetWeaver Application Server (AS) …
Disclosure Date: July 14, 2020 (last updated December 21, 2020)
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
9
Attacker Value
Unknown
CVE-2025-0057
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
0
Attacker Value
Unknown
CVE-2024-47582
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
0
Attacker Value
Unknown
CVE-2024-47580
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.
0
Attacker Value
Unknown
CVE-2024-47579
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability
0
Attacker Value
Unknown
CVE-2024-47578
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.
0
Attacker Value
Unknown
CVE-2024-42372
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2024-45283
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
0
Attacker Value
Unknown
CVE-2024-45280
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
0
Attacker Value
Unknown
CVE-2024-27899
Disclosure Date: April 09, 2024 (last updated April 10, 2024)
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
0