FAIL › dossier
NetWeaver
PRODUCT· dossier confidence 40%
SAP NetWeaver, a core component of SAP's ERP platform, has a significant history of critical security vulnerabilities, including remote code execution and data exposure flaws. Recent updates address critical memory corruption and request smuggling issues, highlighting the ongoing need for diligent patching and security monitoring.
PROFILE
CategoryEnterprise Resource Planning (ERP)What they doSAP is a multinational software corporation that develops enterprise resource planning (ERP) software to manage business operations and customer relations. NetWeaver is a technology platform that enables integration and application development within SAP's ecosystem.OwnershipPublic
Websitehttps://www.sap.com/ ↗
SECURITY POSTURE
SAP NetWeaver has a history of critical vulnerabilities, frequently involving remote code execution and data exposure. The platform's complexity and widespread use make it a frequent target for attackers.
Notable failures
- CVE-2025-31324: Critical RCE via Visual Composer Metadata Uploader
- CVE-2025-42999: High-severity deserialization vulnerability
- CVE-2016-2386: SQL injection vulnerability in UDDI server
- CVE-2010-5326: Unauthenticated remote code execution via Invoker Servlet
- CVE-2026-44747: Critical memory corruption vulnerability (CVSS 9.9)
- CVE-2026-27690: HTTP request/response smuggling flaw in SAP Approuter
Patterns: Repeated remote code execution vulnerabilities; Authentication bypass issues; File upload vulnerabilities; Directory traversal vulnerabilities; XML External Entity (XXE) attacks
FAILURE HISTORY · 11
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-04-29 | CVE-2025-31324 | critical | An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment. |
| 2021-11-03 | CVE-2010-5326 | high | SAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests. |
| 2021-11-03 | CVE-2020-6287 | high | SAP NetWeaver allowed unauthenticated attackers to execute critical configuration tasks and create administrative users. |
| 2021-11-03 | CVE-2016-9563 | high | SAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code. |
| 2025-05-15 | CVE-2025-42999 | high | SAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability. |
| 2022-06-09 | CVE-2016-2388 | high | SAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old. |
| 2022-06-09 | CVE-2021-38163 | high | SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration. |
| 2021-11-03 | CVE-2016-3976 | high | SAP NetWeaver's CrashFileDownloadServlet allowed remote attackers to read arbitrary files via directory traversal. |
| 2022-06-09 | CVE-2016-2386 | high | A SQL injection vulnerability in SAP NetWeaver allowed attackers to execute arbitrary SQL commands remotely. |
| 2025-03-19 | CVE-2017-12637 | high | SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation. |
| 2025-04-24 | CVE-2025-31324 | critical | CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a |
DOSSIER SOURCES
- SAP - Wikipedia · en.wikipedia.org
- SAP warns of critical flaws in NetWeaver and Commerce Cloud · BleepingComputer
- Ransomware Gangs Exploit SAP NetWeaver Vulnerability in Ongoing Global ... · dailysecurityreview.com
- SAP NetWeaver ABAP CVE-2026-44747 - vulert.com · vulert.com
- SAP Security Update July 2026 - Germany · www.europesays.com
- CVE-2026-44747 (CVSS 9.9) SAP NetWeaver CVE-202… | PurpleOps · purple-ops.io
- SAP July 2026 Security Update: NetWeaver & Commerce Cloud Guide · itknowledgelab.com
Open questions: What specific versions of NetWeaver are affected by the documented vulnerabilities? · What is the current patching status of NetWeaver deployments within our organization? · What compensating controls are in place to mitigate the risks associated with NetWeaver vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:47:48.364934+00:00