Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | SAP Netweaver Application Server Java | 26/5/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851. | |
| Modificada | Media (5) | 1.5% | — | SAP Netweaver RFC SDK | 12/5/2015 | 17/6/2026 | SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037. | |
| Modificada | Media (5) | 2.4% | — | SAP Netweaver | 1/4/2015 | 17/6/2026 | The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768. | |
| Modificada | Media (6.5) | 3.7% | — | SAP Netweaver | 1/4/2015 | 17/6/2026 | Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369. | |
| Modificada | Media (5) | 2.5% | — | SAP Netweaver Enterprise Portal | 1/4/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966. | |
| Modificada | Media (5) | 2.4% | — | SAP Netweaver Enterprise Portal | 1/4/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939. | |
| Modificada | Media (5) | 2.2% | — | SAP Netweaver Abap | 22/1/2015 | 17/6/2026 | XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638. | |
| Modificada | Media (4.3) | 1.8% | — | SAP Netweaver Business Client FOR Html | 7/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285. | |
| Modificada | Alta (7.5) | 1.2% | — | SAP Netweaver Business Warehouse | 6/11/2014 | 17/6/2026 | SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 10% | 💥 Exploit | SAP Netweaver | 6/11/2014 | 17/6/2026 | The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion and crash) via a trace level with a wildcard in the Trace Pattern. | |
| Modificada | Media (5) | 2.1% | — | SAP Netweaver | 4/11/2014 | 17/6/2026 | Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via a crafted request. | |
| Modificada | Media (5) | 1.9% | — | SAP Netweaver | 4/11/2014 | 17/6/2026 | Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via unknown vectors. | |
| Modificada | Media (4.3) | 2.2% | — | SAP Netweaver Java Application Server | 4/11/2014 | 17/6/2026 | XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP CommoncryptolibSapcryptolibSapseculibSAP Hana+1 | 4/11/2014 | 17/6/2026 | SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors. | |
| Modificada | Baja (3.5) | 2.1% | — | SAP Netweaver Abap | 16/10/2014 | 17/6/2026 | Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function. | |
| Modificada | Media (6.5) | 2.4% | — | SAP Netweaver | 5/9/2014 | 17/6/2026 | Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated users to cause a denial of service or execute arbitrary code via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.9% | — | SAP Netweaver Business Warehouse | 31/7/2014 | 17/6/2026 | The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | SAP Netweaver Business Client | 13/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) sap-accessibility parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | SAP Netweaver | 9/6/2014 | 17/6/2026 | The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system. | |
| Modificada | Media (5) | 1.4% | — | SAP Netweaver | 19/5/2014 | 17/6/2026 | SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | SAP Netweaver Java Application Server | 30/4/2014 | 17/6/2026 | SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to SystemSelection. | |
| Modificada | Media (4.6) | 0.33% | — | SAP Netweaver Abap Application Server | 30/4/2014 | 17/6/2026 | The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages. | |
| Modificada | Media (5) | 2.3% | — | SAP Netweaver Software Lifecycle Manager | 30/4/2014 | 17/6/2026 | The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1. | |
| Modificada | Alta (7.5) | 1.5% | — | SAP Netweaver | 10/4/2014 | 17/6/2026 | An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and write to arbitrary files via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | SAP Netweaver | 14/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP. |