Netweaver

Vendor:

First CVE: Apr 16, 2008 · Active for 18 years

104
Total CVEs
More Total CVEs than 99% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Netweaver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2008
18 years ago
Most Recent CVE
Feb 10, 2026
165 days ago

CVE Severity & Scoring

Netweaver104 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local2 (1.9%)
Network51 (49.0%)
Unknown50 (48.1%)
Physical0 (0.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low52 (50.0%)
High2 (1.9%)
Unknown50 (48.1%)
User Interaction
None40 (38.5%)
Unknown50 (48.1%)
Required14 (13.5%)
Privileges Required
Low13 (12.5%)
High5 (4.8%)
None36 (34.6%)
Unknown50 (48.1%)

Top CVEs

Signals from CVEs in this product scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha
Apr 24, 20259.898YESYES
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file ov
Sep 14, 20218.882YESNO
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a
May 13, 20259.172YESNO
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Dev
May 15, 20129.372NOYES
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attack
Feb 16, 20167.567NOYES
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports
Jan 23, 20209.853NOYES
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
Sep 6, 20179.840NOYES
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted SOAP request to TCP port 1128.
Aug 16, 20135.035NOYES
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data
Apr 11, 20236.532NONO
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exp
Feb 5, 20209.832NONO

Exploit Exposure

Signals from CVEs in this product scope (104 CVEs).

CISA KEV
3 CVEs
2.9% of CVEs· 96th percentile
Metasploit
2 CVEs
1.9% of CVEs· 96th percentile
Nuclei
2 CVEs
1.9% of CVEs· 96th percentile
ExploitDB
11 CVEs
10.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (104 CVEs).

Media Mentions

Signals from CVEs in this product scope (104 CVEs).

Top CNAs Publishing CVEs For Netweaver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
webdisp_7.5417.50.3%00
webdisp_7.5317.50.3%00
webdisp_7.22ext17.50.3%00
krnl64uc_7.5317.50.3%00
krnl64uc_7.22ext17.50.3%00
krnl64uc_7.2227.51.4%00
krnl64nuc_7.22ext17.50.3%00
krnl64nuc_7.2237.51.1%00
kernel_7.5417.50.3%00
kernel_7.5317.50.3%00
kernel_7.2237.51.1%00
91614.30.2%00
91414.30.2%00
81614.30.2%00
80718.80.9%00
80618.80.9%00
80518.80.9%00
80418.80.9%00
80318.80.9%00
80218.80.9%00