Webdispatcher

Vendor:

First CVE: Jul 14, 2021 · Active for 5 years

12
Total CVEs
Bottom 1%
3.0
Avg CVEs / Year
Bottom 1%
7.7
Avg CVSS
Higher Avg CVSS than 25% of tracked products
8.3%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webdispatcher over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Aug 13, 2024
714 days ago

CVE Severity & Scoring

Webdispatcher12 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None10 (83.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and
Feb 9, 202210.098YESYES
SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes al
Sep 14, 20219.430NONO
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation o
Sep 12, 20239.827NONO
The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54 KERNEL 7.
Jul 11, 20239.427NONO
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP
Jul 11, 20239.426NONO
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automat
Apr 12, 20227.524NONO
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes t
Sep 12, 20237.522NONO
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting
May 11, 20226.121NONO
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can im
Aug 13, 20246.319NONO
The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable ac
Apr 11, 20235.319NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
1 CVE
8.3% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Webdispatcher

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
xs_advanced_runtime_1.0029.40.7%00
webdisp_7.9316.30.2%00
webdisp_7.8916.30.2%00
webdisp_7.8516.30.2%00
webdisp_7.7716.30.2%00
webdisp_7.5416.30.2%00
webdisp_7.5325.30.4%00
webdisp_7.22_ext16.30.2%00
sap_extended_app_services_129.40.7%00
krnl64uc_7.5338.40.5%00
krnl64uc_7.4919.40.7%00
krnl64uc_7.22ext16.30.2%00
krnl64uc_7.2227.81.5%00
krnl64uc_7.2114.30.5%00
krnl64nuc_7.4919.40.7%00
krnl64nuc_7.22ext16.30.2%00
krnl64nuc_7.2227.81.5%00
krnl64nuc_7.2114.30.5%00
krnl32uc_7.2114.30.5%00
krnl32nuc_7.2114.30.5%00