Known Vulnerabilities for Netweaver Process Integration by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Netweaver Process Integration" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-37488 json | In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if n... | 6.1 - MEDIUM | 2023-08-08 | 2023-08-15 |
| CVE-2023-35873 json | The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication... | 6.5 - MEDIUM | 2023-07-11 | 2023-07-19 |
| CVE-2023-35872 json | The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authenticatio... | 6.5 - MEDIUM | 2023-07-11 | 2023-07-19 |
| CVE-2022-41272 json | An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search ... | 8.6 - HIGH | 2022-12-13 | 2023-11-07 |
| CVE-2022-41271 json | An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process... | 9.4 - CRITICAL | 2022-12-13 | 2023-11-07 |
| CVE-2021-27618 json | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not ch... | 4.9 - MEDIUM | 2021-05-11 | 2021-08-27 |
| CVE-2021-27617 json | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not su... | 4.9 - MEDIUM | 2021-05-11 | 2022-06-28 |
| CVE-2021-27604 json | In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - E... | 6.5 - MEDIUM | 2021-04-14 | 2021-08-27 |
| CVE-2021-27599 json | SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.3... | 6.5 - MEDIUM | 2021-04-14 | 2022-06-28 |
| CVE-2019-0367 json | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks... | 4.3 - MEDIUM | 2019-10-08 | 2019-10-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Process Integration | 7.50 | |||
| Application | Sap | Netweaver Process Integration | 7.5 | |||
| Application | Sap | Netweaver Process Integration | 7.40 | |||
| Application | Sap | Netweaver Process Integration | 7.4 | |||
| Application | Sap | Netweaver Process Integration | 7.31 | |||
| Application | Sap | Netweaver Process Integration | 7.30 | |||
| Application | Sap | Netweaver Process Integration | 7.3 | |||
| Application | Sap | Netweaver Process Integration | 7.20 | |||
| Application | Sap | Netweaver Process Integration | 7.11 | |||
| Application | Sap | Netweaver Process Integration | 7.10 | |||
| Application | Sap | Netweaver Process Integration | 7.1 | |||
| Application | Sap | Netweaver Process Integration | 7.0 | |||
| Application | Sap | Netweaver Process Integration | 2.0 | |||
| Application | Sap | Netweaver Process Integration | 1.0 |