Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | SAP Netweaver AS Abap Business Server Pages | 24/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs. | |
| Modificada | Alta (8.8) | 1.1% | — | SAP Netweaver Knowledge Management AND Collaboration (kmc-cm)SAP Netweaver Knowledge Management AND Collaboration (kmc-wpc) | 14/4/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through to the file APIs, allowing the attacker… | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.6% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Netweaver AS Abap Business Server Pages | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.2) | 1.1% | — | SAP Netweaver Application Server Java | 14/4/2020 | 17/6/2026 | SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure. | |
| Modificada | Media (6.1) | 0.77% | — | SAP Netweaver AS Abap Business Server Pages | 10/3/2020 | 17/6/2026 | SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal… | |
| Modificada | Crítica (9.1) | 1.9% | — | SAP Netweaver | 10/3/2020 | 17/6/2026 | SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal. | |
| Modificada | Alta (7.2) | 1.1% | — | SAP Netweaver Application Server Java | 10/3/2020 | 17/6/2026 | SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation. | |
| Modificada | Media (4.3) | 0.62% | — | SAP Netweaver Application Server | 9/3/2020 | 17/6/2026 | nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI. | |
| Modificada | Media (6.1) | 0.71% | — | SAP Netweaver Knowledge Management | 12/2/2020 | 17/6/2026 | SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (5.8) | 0.90% | — | SAP Netweaver Application Server Java | 12/2/2020 | 17/6/2026 | Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure. | |
| Modificada | Media (4.9) | 0.86% | — | SAP Netweaver Guided Procedures | 12/2/2020 | 17/6/2026 | SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service. | |
| Modificada | Media (5.4) | 0.54% | — | SAP NetweaverSAP S/4hana | 12/2/2020 | 17/6/2026 | Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability. | |
| Modificada | Media (6.1) | 0.96% | — | SAP NetweaverSAP S/4hana | 12/2/2020 | 17/6/2026 | Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (5.8) | 0.78% | — | SAP Abap PlatformSAP Netweaver | 12/2/2020 | 17/6/2026 | Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting… | |
| Modificada | Crítica (9.8) | 4.2% | — | SAP Netweaver | 5/2/2020 | 16/6/2026 | SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash. | |
| Modificada | Alta (7.5) | 2.4% | — | SAP Netweaver | 23/1/2020 | 16/6/2026 | A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN. | |
| Modificada | Crítica (9.8) | 24% | 💥 Exploit | SAP Netweaver | 23/1/2020 | 16/6/2026 | A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver Internet Communication Manager (kernel)SAP Netweaver Internet Communication Manager (krnl32nuc)SAP Netweaver Internet Communication Manager (krnl32uc)SAP Netweaver Internet Communication Manager (krnl64nuc)+1 | 14/1/2020 | 17/6/2026 | Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an attacker to prevent users from accessing its services through a denial of service. | |
| Modificada | Media (4.3) | 0.89% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise. | |
| Modificada | Media (4.3) | 0.55% | — | SAP Netweaver Process Integration | 8/10/2019 | 17/6/2026 | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check. | |
| Modificada | Media (4.3) | 0.70% | — | SAP Netweaver Process Integration | 10/9/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (7.2) | 1.6% | — | SAP Netweaver Application Server Java | 10/9/2019 | 17/6/2026 | SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application. |