SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSap Netweaver
APPSap7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
Related vulnerabilities
CVE-2025-42999CRITICAL9.1⚠ KEVPL ✓same product
SAP NetWeaver Visual Composer — niebezpieczna deserializacja treści
CVE-2025-31324CRITICAL10.0⚠ KEVPL ✓same product
SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer
CVE-2021-38163CRITICAL9.9⚠ KEVPL ✓same product
SAP NetWeaver Visual Composer — RCE przez path traversal przy uploadzie pliku
CVE-2023-36922CRITICAL9.1PL ✓same product
Command injection w SAP ECC i S/4HANA — komponent IS-OIL
CVE-2020-6203CRITICAL9.1PL ✓same product
Path Traversal w SAP NetWeaver UDDI Server (Services Registry)