SAP netweaver application server java Vulnerabilities
CVE security advisories and vulnerability history for netweaver application server java by SAP.
70
Total CVEs
Published
7
In CISA KEV
Exploited in the wild
14
Public exploits
PoC or exploit code
7.0
Avg CVSS
2016–2026
Last updated
Overview
SAP netweaver application server java has 70 published CVE records since 2016, of which 7 are in CISA's Known Exploited Vulnerabilities catalog and 14 have a known public exploit. The average CVSS base score across scored CVEs is 7.0.
This page aggregates every publicly disclosed vulnerability (CVE) affecting SAP netweaver application server java, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of SAP netweaver application server java's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical11
High22
Medium36
Low1
In CISA’s Known Exploited Vulnerabilities catalog
7
7 of SAP netweaver application server java's CVEs are confirmed exploited in the wild.
Public exploits
14
14 of SAP netweaver application server java's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every SAP netweaver application server java version named in a CVE, then pick one to see only the CVEs that affect it.
Version ranges
7.50 <= v <= 7.5048 CVEs
7.40 <= v <= 7.4035 CVEs
7.31 <= v <= 7.3133 CVEs
7.30 <= v <= 7.3031 CVEs
7.20 <= v <= 7.2024 CVEs
7.10 <= v <= 7.1019 CVEs
7.11 <= v <= 7.1116 CVEs
7.10 <= v <= 7.505 CVEs
7.22 <= v <= 7.223 CVEs
7.49 <= v <= 7.493 CVEs
7.53 <= v <= 7.533 CVEs
Common weakness types
The CWE weakness categories most often found in SAP netweaver application server java CVEs. Follow any weakness for its full explanation.
Common questions about SAP netweaver application server java vulnerabilities.
How many CVEs does SAP netweaver application server java have?
SAP netweaver application server java has 70 published CVE records since 2016.
How many SAP netweaver application server java CVEs are in CISA KEV?
Yes — 7 of SAP netweaver application server java's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for SAP netweaver application server java vulnerabilities?
Yes — 14 of SAP netweaver application server java's CVEs have a known public exploit.
Which versions of SAP netweaver application server java are affected?
45 distinct SAP netweaver application server java versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in SAP netweaver application server java CVEs?
SAP netweaver application server java's CVEs most often map to these CWE weakness types: CWE-306 (Missing Authentication for Critical Function), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-611 (Improper Restriction of XML External Entity Reference), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How many critical SAP netweaver application server java vulnerabilities are there?
SAP netweaver application server java has 11 critical and 22 high-severity CVEs.
What is the average severity of SAP netweaver application server java CVEs?
The average CVSS base score across SAP netweaver application server java's scored CVEs is 7.0.