Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.85% | — | SAP Netweaver Process Integration | 11/5/2021 | 17/6/2026 | The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicious XML which when uploaded and parsed by the application, could lead to Denial-of-service… | |
| Modificada | Media (6.7) | 0.27% | — | SAP Netweaver Application Server Abap | 11/5/2021 | 17/6/2026 | SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to data, overwrite them, or execute a denial of service. | |
| Modificada | Media (6.5) | 0.79% | — | SAP Netweaver Process Integration | 14/4/2021 | 17/6/2026 | In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refer this note. | |
| Modificada | Media (6.5) | 0.81% | — | SAP Netweaver Process Integration | 14/4/2021 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would otherwise be restricted. | |
| Modificada | Media (6.5) | 0.86% | — | SAP Netweaver Application Server Abap | 13/4/2021 | 17/6/2026 | An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the… | |
| Modificada | Media (5.4) | 0.47% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have… | |
| Modificada | Media (5.3) | 0.64% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet. | |
| Modificada | Media (4.3) | 0.56% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled. | |
| Modificada | Media (6.5) | 0.94% | — | SAP Netweaver Application Server Java | 13/4/2021 | 17/6/2026 | An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user. | |
| Modificada | Alta (8.3) | 0.42% | — | SAP Netweaver Master Data Management | 13/4/2021 | 17/6/2026 | SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the password using a brute force method. If successful, the attacker could obtain access to highly sensitive data and MDM administrative privileges leading to information… | |
| Modificada | Media (6.1) | 0.69% | — | SAP Netweaver Application Server Java | 10/3/2021 | 17/6/2026 | SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. | |
| Modificada | Media (6.5) | 1.3% | — | SAP Netweaver Knowledge Management | 9/3/2021 | 17/6/2026 | Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability. | |
| Modificada | Alta (8.8) | 0.51% | — | SAP Netweaver | 9/3/2021 | 17/6/2026 | The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of… | |
| Modificada | Alta (7.5) | 1.9% | — | SAP Netweaver Master Data Management Server | 9/2/2021 | 17/6/2026 | Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. Due to this Directory Traversal… | |
| Modificada | Alta (7.5) | 1.2% | — | SAP Netweaver Master Data Management | 12/1/2021 | 17/6/2026 | When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not… | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver Application Server Abap | 12/1/2021 | 17/6/2026 | SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service. | |
| Modificada | Media (6.1) | 0.82% | — | SAP Netweaver Application Server Abap | 9/12/2020 | 17/6/2026 | SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.6) | 2.2% | — | SAP Netweaver Application Server AbapSAP S/4 Hana | 9/12/2020 | 17/6/2026 | SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be… | |
| Modificada | Crítica (10) | 4.8% | — | SAP Netweaver Application Server Java | 9/12/2020 | 17/6/2026 | SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an… | |
| Modificada | Media (6.5) | 1.2% | — | SAP Netweaver Application Server Java | 9/12/2020 | 17/6/2026 | Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload. | |
| Modificada | Media (4.5) | 0.17% | — | SAP Netweaver Application Server Java | 9/12/2020 | 17/6/2026 | SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver… | |
| Modificada | Alta (7.2) | 3.9% | — | SAP Netweaver Application Server Java | 10/11/2020 | 17/6/2026 | SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS… | |
| Modificada | Alta (8.8) | 0.94% | — | SAP Netweaver Application Server Abap | 10/11/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control. | |
| Modificada | Alta (8.8) | 1.2% | — | SAP Netweaver Application Server Abap | 10/11/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information… | |
| Modificada | Media (4.8) | 0.53% | — | SAP Netweaver Design Time Repository | 20/10/2020 | 17/6/2026 | SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |