Known Vulnerabilities for Netweaver Application Server For Java by Sap
Listed below are 9 of the newest known vulnerabilities associated with "Netweaver Application Server For Java" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-27674 json | Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker... | Not Provided | 2026-04-14 | 2026-04-15 |
| CVE-2023-31405 json | SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to c... | 5.3 - MEDIUM | 2023-07-11 | 2023-07-18 |
| CVE-2023-30744 json | In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach ... | 9.1 - CRITICAL | 2023-05-09 | 2023-11-07 |
| CVE-2023-27268 json | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an... | 5.3 - MEDIUM | 2023-03-14 | 2023-04-11 |
| CVE-2023-26460 json | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication che... | 5.3 - MEDIUM | 2023-03-14 | 2023-04-11 |
| CVE-2023-23857 json | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach t... | 8.6 - HIGH | 2023-03-14 | 2023-04-11 |
| CVE-2023-0017 json | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an ope... | 9.8 - CRITICAL | 2023-01-10 | 2023-01-13 |
| CVE-2022-27669 json | An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - versio... | 7.5 - HIGH | 2022-04-12 | 2022-04-20 |
| CVE-2021-27635 json | SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to c... | 6.5 - MEDIUM | 2021-06-09 | 2021-11-04 |
| CVE-2021-27621 json | Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7... | 4.9 - MEDIUM | 2021-06-09 | 2022-07-12 |