Known Vulnerabilities for Netweaver Enterprise Portal by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Netweaver Enterprise Portal" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-28761 json | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use... | 6.5 - MEDIUM | 2023-04-11 | 2023-04-14 |
| CVE-2023-26461 json | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to a... | 4.9 - MEDIUM | 2023-03-14 | 2023-04-11 |
| CVE-2022-35298 json | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross... | 6.1 - MEDIUM | 2022-09-13 | 2022-10-01 |
| CVE-2022-35227 json | A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled in... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-35225 json | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-35172 json | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-19 |
| CVE-2022-35170 json | SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-contro... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-32247 json | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attac... | 6.1 - MEDIUM | 2022-07-12 | 2022-07-20 |
| CVE-2022-26105 json | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attac... | 6.1 - MEDIUM | 2022-04-12 | 2022-04-19 |
| CVE-2022-24397 json | SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resul... | 6.1 - MEDIUM | 2022-03-10 | 2022-03-16 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Enterprise Portal | 7.31 |