Webdispatcher
Vendor:
First CVE: Jul 14, 2021 · Active for 5 years
12
Total CVEs
Bottom 1%
3.0
Avg CVEs / Year
Bottom 1%
7.7
Avg CVSS
Higher Avg CVSS than 25% of tracked products
8.3%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webdispatcher over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Aug 13, 2024
714 days ago
CVE Severity & Scoring
Webdispatcher12 CVEs
33%
25%
42%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None10 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22536CRITICAL SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and | Feb 9, 2022 | 10.0 | 98 | YES | YES |
CVE-2021-38162CRITICAL SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes al | Sep 14, 2021 | 9.4 | 30 | NO | NO |
CVE-2023-40309CRITICAL SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation o | Sep 12, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-35871CRITICAL The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54 KERNEL 7. | Jul 11, 2023 | 9.4 | 27 | NO | NO |
CVE-2023-33987CRITICAL An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP | Jul 11, 2023 | 9.4 | 26 | NO | NO |
CVE-2022-28773HIGH Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automat | Apr 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-40308HIGH SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes t | Sep 12, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-27656MEDIUM The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting | May 11, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-33005MEDIUM Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can im | Aug 13, 2024 | 6.3 | 19 | NO | NO |
CVE-2023-29108MEDIUM The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable ac | Apr 11, 2023 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
1 CVE
8.3% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Webdispatcher
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| xs_advanced_runtime_1.00 | 2 | 9.4 | 0.7% | 0 | 0 |
| webdisp_7.93 | 1 | 6.3 | 0.2% | 0 | 0 |
| webdisp_7.89 | 1 | 6.3 | 0.2% | 0 | 0 |
| webdisp_7.85 | 1 | 6.3 | 0.2% | 0 | 0 |
| webdisp_7.77 | 1 | 6.3 | 0.2% | 0 | 0 |
| webdisp_7.54 | 1 | 6.3 | 0.2% | 0 | 0 |
| webdisp_7.53 | 2 | 5.3 | 0.4% | 0 | 0 |
| webdisp_7.22_ext | 1 | 6.3 | 0.2% | 0 | 0 |
| sap_extended_app_services_1 | 2 | 9.4 | 0.7% | 0 | 0 |
| krnl64uc_7.53 | 3 | 8.4 | 0.5% | 0 | 0 |
| krnl64uc_7.49 | 1 | 9.4 | 0.7% | 0 | 0 |
| krnl64uc_7.22ext | 1 | 6.3 | 0.2% | 0 | 0 |
| krnl64uc_7.22 | 2 | 7.8 | 1.5% | 0 | 0 |
| krnl64uc_7.21 | 1 | 4.3 | 0.5% | 0 | 0 |
| krnl64nuc_7.49 | 1 | 9.4 | 0.7% | 0 | 0 |
| krnl64nuc_7.22ext | 1 | 6.3 | 0.2% | 0 | 0 |
| krnl64nuc_7.22 | 2 | 7.8 | 1.5% | 0 | 0 |
| krnl64nuc_7.21 | 1 | 4.3 | 0.5% | 0 | 0 |
| krnl32uc_7.21 | 1 | 4.3 | 0.5% | 0 | 0 |
| krnl32nuc_7.21 | 1 | 4.3 | 0.5% | 0 | 0 |