Known vulnerabilities in SAP Web Dispatcher WEBDISP

Vendor: SAP
Software CPE: cpe:2.3:a:sap:sap_web_dispatcher_webdisp:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SAP Web Dispatcher WEBDISP SAP Web Dispatcher WEBDISP is affected by 9 known vulnerabilities: 1 critical, 1 high, 4 medium, 3 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119389 - Memory corruption
CVE-2025-42877
CWE-119 Medium
No
No
- 09.12.2025 SB2025120911
#VU119388 - Exposure of sensitive information to an unauthorized actor
CVE-2025-42878
CWE-200 Low
No
No
- 09.12.2025 SB2025120910
#VU105503 - Exposure of sensitive information to an unauthorized actor
CVE-2025-0071
CWE-200 Low
No
No
- 11.03.2025 SB2025031135
#VU100240 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47590
CWE-79 Low
No
No
- 12.11.2024 SB2024111250
#VU78958 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-22536
CWE-444 Critical
Available
Exploited
- 04.08.2023 SB2022021025
#VU78729 - Memory corruption
CVE-2023-35871
CWE-119 High
No
No
- 27.07.2023 SB2023072756
#VU78724 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-33987
CWE-444 Medium
No
No
- 27.07.2023 SB2023072755
#VU75157 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2023-29108
CWE-923 Medium
No
No
- 17.04.2023 SB2023041711
#VU75156 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-33683
CWE-444 Medium
No
No
- 17.04.2023 SB2023041710