Skip to content
COOEY

FAIL › dossier

NetWeaver

PRODUCT

· dossier confidence 40%

SAP NetWeaver, a core component of SAP's ERP platform, has a significant history of critical security vulnerabilities, including remote code execution and data exposure flaws. Recent updates address critical memory corruption and request smuggling issues, highlighting the ongoing need for diligent patching and security monitoring.

PROFILE
CategoryEnterprise Resource Planning (ERP)What they doSAP is a multinational software corporation that develops enterprise resource planning (ERP) software to manage business operations and customer relations. NetWeaver is a technology platform that enables integration and application development within SAP's ecosystem.OwnershipPublic Websitehttps://www.sap.com/ ↗
SECURITY POSTURE

SAP NetWeaver has a history of critical vulnerabilities, frequently involving remote code execution and data exposure. The platform's complexity and widespread use make it a frequent target for attackers.

Notable failures
  • CVE-2025-31324: Critical RCE via Visual Composer Metadata Uploader
  • CVE-2025-42999: High-severity deserialization vulnerability
  • CVE-2016-2386: SQL injection vulnerability in UDDI server
  • CVE-2010-5326: Unauthenticated remote code execution via Invoker Servlet
  • CVE-2026-44747: Critical memory corruption vulnerability (CVSS 9.9)
  • CVE-2026-27690: HTTP request/response smuggling flaw in SAP Approuter
Patterns: Repeated remote code execution vulnerabilities; Authentication bypass issues; File upload vulnerabilities; Directory traversal vulnerabilities; XML External Entity (XXE) attacks
FAILURE HISTORY · 11
DATEEVENTSEVSUMMARY
2025-04-29 CVE-2025-31324 critical An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment.
2021-11-03 CVE-2010-5326 high SAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests.
2021-11-03 CVE-2020-6287 high SAP NetWeaver allowed unauthenticated attackers to execute critical configuration tasks and create administrative users.
2021-11-03 CVE-2016-9563 high SAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code.
2025-05-15 CVE-2025-42999 high SAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability.
2022-06-09 CVE-2016-2388 high SAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old.
2022-06-09 CVE-2021-38163 high SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration.
2021-11-03 CVE-2016-3976 high SAP NetWeaver's CrashFileDownloadServlet allowed remote attackers to read arbitrary files via directory traversal.
2022-06-09 CVE-2016-2386 high A SQL injection vulnerability in SAP NetWeaver allowed attackers to execute arbitrary SQL commands remotely.
2025-03-19 CVE-2017-12637 high SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation.
2025-04-24 CVE-2025-31324 critical CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper a
Open questions: What specific versions of NetWeaver are affected by the documented vulnerabilities? · What is the current patching status of NetWeaver deployments within our organization? · What compensating controls are in place to mitigate the risks associated with NetWeaver vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:47:48.364934+00:00