Netweaver Application Server For Java
Vendor:
First CVE: Jun 9, 2021 · Active for 5 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Netweaver Application Server For Java over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2021
5 years ago
Most Recent CVE
Jul 11, 2023
1,109 days ago
CVE Severity & Scoring
Netweaver Application Server For Java9 CVEs
56%
22%
22%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (22.2%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0017CRITICAL An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and director | Jan 10, 2023 | 9.8 | 39 | NO | NO |
CVE-2023-23857HIGH Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and | Mar 14, 2023 | 8.6 | 28 | NO | NO |
CVE-2023-30744CRITICAL In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and | May 9, 2023 | 9.1 | 27 | NO | NO |
CVE-2022-27669HIGH An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may | Apr 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-27635MEDIUM SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XM | Jun 9, 2021 | 6.5 | 21 | NO | NO |
CVE-2023-31405MEDIUM SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unw | Jul 11, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-27268MEDIUM SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interfac | Mar 14, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-26460MEDIUM Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
| Mar 14, 2023 | 5.3 | 19 | NO | NO |
CVE-2021-27621MEDIUM Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access | Jun 9, 2021 | 4.9 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Netweaver Application Server For Java
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.50 | 9 | 6.9 | 2.4% | 0 | 0 |
| 7.40 | 2 | 5.7 | 1.1% | 0 | 0 |
| 7.31 | 2 | 5.7 | 1.1% | 0 | 0 |
| 7.30 | 2 | 5.7 | 1.1% | 0 | 0 |
| 7.20 | 2 | 5.7 | 1.1% | 0 | 0 |
| 7.11 | 1 | 4.9 | 0.6% | 0 | 0 |