Netweaver Application Server Java

Vendor:

First CVE: Feb 16, 2016 · Active for 10 years

69
Total CVEs
More Total CVEs than 98% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
10.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Netweaver Application Server Java over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2016
10 years ago
Most Recent CVE
Apr 14, 2026
101 days ago

CVE Severity & Scoring

Netweaver Application Server Java69 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network67 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (2.9%)
Attack Complexity
Low68 (98.6%)
High1 (1.4%)
Unknown0 (0.0%)
User Interaction
None53 (76.8%)
Unknown0 (0.0%)
Required16 (23.2%)
Privileges Required
Low15 (21.7%)
High9 (13.0%)
None45 (65.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication t
Jul 14, 202010.098YESYES
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary file
Aug 7, 20177.596YESYES
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security
Feb 16, 20169.895YESYES
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter t
Apr 7, 20167.587YESYES
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 225
Feb 16, 20165.387YESYES
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary cod
May 13, 201610.078YESNO
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlc
Nov 23, 20166.572YESNO
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay
Apr 7, 20169.147NOYES
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication chec
Dec 9, 202010.032NONO
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could s
Feb 9, 20229.831NONO

Exploit Exposure

Signals from CVEs in this product scope (69 CVEs).

CISA KEV
7 CVEs
10.1% of CVEs· 97th percentile
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
2 CVEs
2.9% of CVEs· 96th percentile
ExploitDB
4 CVEs
5.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (69 CVEs).

Media Mentions

Signals from CVEs in this product scope (69 CVEs).

Top CNAs Publishing CVEs For Netweaver Application Server Java

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
mmr_server_7.517.50.5%00
krnl64uc_7.4928.72.1%00
krnl64uc_7.22ext28.72.1%00
krnl64uc_7.2228.72.1%00
krnl64nuc_7.4928.72.1%00
krnl64nuc_7.22ext28.72.1%00
krnl64nuc_7.2228.72.1%00
kernel_8.0428.70.7%00
kernel_7.9328.70.7%00
kernel_7.9228.70.7%00
kernel_7.9128.70.7%00
kernel_7.8928.70.7%00
kernel_7.8528.70.7%00
kernel_7.7728.70.7%00
kernel_7.5428.70.7%00
kernel_7.5328.70.7%00
kernel_7.2228.70.7%00
kernel64uc_8.0428.70.7%00
kernel64uc_7.5328.70.7%00
kernel64uc_7.22ext28.70.7%00