Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | SAP Netweaver Composite Application Framework | 20/10/2020 | 17/6/2026 | There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that the script should not… | |
| Modificada | Media (6.5) | 1.1% | — | SAP Netweaver Compare Systems | 20/10/2020 | 17/6/2026 | SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS level from the server and/or can execute a denial-of-service. | |
| Modificada | Media (6.1) | 1.1% | — | SAP Netweaver Application Server Java | 15/10/2020 | 17/6/2026 | SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect… | |
| Modificada | Media (4.3) | 0.90% | — | SAP Netweaver Application Server Abap | 15/10/2020 | 17/6/2026 | User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver Enterprise Portal | 15/10/2020 | 17/6/2026 | SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the system, resulting in… | |
| Modificada | Media (6.1) | 0.91% | — | SAP Netweaver Application Server Java | 15/10/2020 | 17/6/2026 | SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successful exploitation an attacker can steal authentication information of… | |
| Modificada | Media (6.1) | 0.90% | — | SAP Netweaver AS Abap Business Server Pages | 9/9/2020 | 17/6/2026 | SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacker to send polluted URL to the victim, when the victim clicks on this URL, the attacker can read, modify the information available in the victim�s browser leading to… | |
| Modificada | Media (5.4) | 0.65% | — | SAP Netweaver Knowledge Management | 9/9/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting. | |
| Modificada | Media (6.5) | 0.72% | — | SAP Netweaver Application Server Java | 9/9/2020 | 17/6/2026 | SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store malicious content, that when accessed by a victim, can perform malicious actions by executing JavaScript, leading to… | |
| Modificada | Media (4.3) | 0.94% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 12/8/2020 | 17/6/2026 | Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure. | |
| Modificada | Alta (7.5) | 1.8% | — | SAP Netweaver Application Server Java | 12/8/2020 | 17/6/2026 | SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several payloads and leading to complete denial of service. | |
| Modificada | Media (4.3) | 0.90% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 12/8/2020 | 17/6/2026 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 12/8/2020 | 17/6/2026 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application. | |
| Modificada | Media (6.5) | 0.93% | — | SAP Netweaver Knowledge Management | 12/8/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and… | |
| Modificada | Crítica (9) | 1.8% | — | SAP Netweaver Knowledge Management | 12/8/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in… | |
| Analizada | Crítica (10) | 95% | ⚠ Explotación activa💥 Exploit | SAP Netweaver Application Server Java | 14/7/2020 | 17/6/2026 | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative… | |
| Modificada | Media (5.3) | 28% | 💥 PoC | SAP Netweaver Application Server Java | 14/7/2020 | 17/6/2026 | The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal. | |
| Modificada | Media (6.5) | 1.1% | — | SAP Netweaver | 14/7/2020 | 17/6/2026 | SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure. | |
| Modificada | Media (5.8) | 1.1% | — | SAP Netweaver Application Server Java | 14/7/2020 | 17/6/2026 | SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send a crafted request from a vulnerable web application. It is usually used to target… | |
| Modificada | Baja (2.7) | 0.94% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 14/7/2020 | 17/6/2026 | SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure. | |
| Modificada | Crítica (9.8) | 1.4% | — | SAP Netweaver Application Server Abap | 10/6/2020 | 17/6/2026 | SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attack where in an attacker can use inappropriate path names containing malicious server names in the import/export of sessions functionality and coerce the web server into… | |
| Modificada | Media (6.5) | 0.80% | — | SAP Netweaver Application Server Abap | 10/6/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong… | |
| Modificada | Crítica (9.8) | 1.4% | — | SAP Netweaver Application Server Java | 10/6/2020 | 17/6/2026 | Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity… | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 10/6/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Netweaver Application Server Abap | 12/5/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service |