Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.44% | — | SAP Abap Development ToolsAISAP Netweaver AS AbapAI | 11/8/2026 | 26/8/2026 | SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and… | |
| Analizada | Baja (3.1) | 0.25% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc | 10/2/2026 | 17/6/2026 | Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the… | |
| Analizada | Crítica (9.6) | 0.36% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc | 10/2/2026 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the… | |
| Aplazada | Media (5.3) | 0.37% | — | SAP Netweaver AS AbapAISAP Abap PlatformAI | 14/10/2025 | 17/6/2026 | Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the… | |
| Analizada | Media (6.1) | 0.47% | — | SAP Netweaver AS Abap | 12/3/2024 | 17/6/2026 | Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s… | |
| Modificada | Media (6.5) | 0.57% | — | SAP Netweaver AS Abap Business Server Pages | 11/4/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This… | |
| Modificada | Crítica (9.8) | 2.2% | — | SAP Netweaver AS AbapSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64ucSAP Router | 14/6/2022 | 17/6/2026 | Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53,… | |
| Modificada | Alta (7.5) | 0.96% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc | 11/5/2022 | 17/6/2026 | SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption. | |
| Modificada | Media (6.1) | 0.57% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64ucSAP Webdispatcher | 11/5/2022 | 17/6/2026 | The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Netweaver AbapSAP Netweaver AS Abap | 9/2/2022 | 17/6/2026 | SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver AS Abap | 9/6/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted… | |
| Modificada | Media (6.1) | 0.90% | — | SAP Netweaver AS Abap Business Server Pages | 9/9/2020 | 17/6/2026 | SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to… | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 10/6/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.80% | — | SAP Netweaver AS Abap Business Server Pages | 24/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.6% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |