📦 Netweaver

by Sap

🔍 What is Netweaver?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-42999

CRITICAL CVSS 9.1 May 13, 2025

CVE-2025-42999 is a deserialization vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows privileged users to upload malicious content, potentially leading to remote code execut...

CVE-2025-31324

CRITICAL CVSS 10.0 Apr 24, 2025

CVE-2025-31324 is an unauthenticated remote code execution vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows attackers to upload malicious binaries and execute arbitrary cod...

CVE-2023-36922

CRITICAL CVSS 9.1 Jul 11, 2023

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on SAP ECC and S/4HANA systems with IS-OIL component. Successful exploitation enables attackers to read...

CVE-2021-38163

CRITICAL CVSS 9.9 Sep 14, 2021

CVE-2021-38163 is a critical vulnerability in SAP NetWeaver Visual Composer that allows authenticated non-administrative users to upload malicious files and execute arbitrary operating system commands...

CVE-2023-29186

HIGH CVSS 8.7 Apr 11, 2023

This vulnerability allows attackers with administrative privileges to exploit a directory traversal flaw in SAP NetWeaver BI CONT ADDON reports to upload and overwrite files on the SAP server. While d...

CVE-2022-28773

HIGH CVSS 7.5 Apr 12, 2022

CVE-2022-28773 is an uncontrolled recursion vulnerability in SAP Web Dispatcher and SAP Internet Communication Manager that can cause a denial of service through application crashes. The affected comp...

CVE-2022-28772

HIGH CVSS 7.5 Apr 12, 2022

CVE-2022-28772 is a stack-based buffer overflow vulnerability in SAP Web Dispatcher and Internet Communication Manager. Attackers can send overlong input values to overwrite the program stack, causing...

CVE-2026-23685

MEDIUM CVSS 4.4 Feb 10, 2026

This CVE describes a deserialization vulnerability in SAP NetWeaver's JMS service that allows authenticated administrators with local access to submit malicious content. If processed, this could trigg...

CVE-2025-42968

MEDIUM CVSS 5.0 Jul 8, 2025

This vulnerability in SAP NetWeaver allows authenticated non-administrative users to call a remote-enabled function module that reveals non-sensitive system and OS information. It affects SAP NetWeave...