Netweaver Process Integration

Vendor:

First CVE: Apr 10, 2019 · Active for 7 years

21
Total CVEs
More Total CVEs than 94% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Netweaver Process Integration over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2019
7 years ago
Most Recent CVE
Mar 12, 2024
867 days ago

CVE Severity & Scoring

Netweaver Process Integration21 CVEs
All CVEs352,727 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (81.0%)
Unknown0 (0.0%)
Required4 (19.0%)
Privileges Required
Low6 (28.6%)
High4 (19.0%)
None11 (52.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make us
Dec 13, 20229.429NONO
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - versi
Dec 13, 20228.628NONO
ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights.
Jul 10, 20197.224NONO
Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 t
Jun 12, 20197.524NONO
SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML
Apr 10, 20197.123NONO
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user ide
Jul 11, 20236.520NONO
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user id
Jul 11, 20236.520NONO
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions -
Apr 14, 20216.520NONO
SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information
Apr 14, 20216.520NONO
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50)
Jun 12, 20195.320NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Netweaver Process Integration

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.50196.00.8%00
7.517.23.4%00
7.40135.50.9%00
7.417.23.4%00
7.31145.61.1%00
7.30125.60.9%00
7.317.23.4%00
7.2085.30.9%00
7.11105.50.9%00
7.10125.60.9%00
7.117.23.4%00
7.017.23.4%00
2.014.30.5%00
1.014.30.5%00