CVE-2015-7239: SAP NetWeaver j2ee Engine

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected products

  • SAP NetWeaver j2ee Engine: version 7.40 only

Published 2015-09-18. Last modified 2026-06-17.