Known Vulnerabilities for Netweaver Enterprise Portal by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Netweaver Enterprise Portal" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-28761 | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use... | 6.5 - MEDIUM | 2023-04-11 | 2023-04-14 |
| CVE-2023-26461 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to a... | 4.9 - MEDIUM | 2023-03-14 | 2023-04-11 |
| CVE-2022-35298 | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross... | 6.1 - MEDIUM | 2022-09-13 | 2022-10-01 |
| CVE-2022-35227 | A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled in... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-35225 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-35172 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-19 |
| CVE-2022-35170 | SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-32247 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attac... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-26105 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attac... | 6.1 - MEDIUM | 2022-04-12 | 2022-04-19 |
| CVE-2022-24397 | SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resul... | 6.1 - MEDIUM | 2022-03-10 | 2022-03-16 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Enterprise Portal | 7.31 |