Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Pivotal Software Application Service | 7/3/2019 | 17/6/2026 | Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's DNS record could intercept access tokens… | |
| Modificada | Alta (7.5) | 1.8% | — | SAP Hana Extended Application Services | 15/2/2019 | 17/6/2026 | Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased. | |
| Modificada | Alta (8.8) | 0.96% | — | Pivotal Software Pivotal Application Service | 17/9/2018 | 17/6/2026 | Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential,… | |
| Modificada | Alta (8.8) | 0.96% | — | Pivotal Software Pivotal Application Service | 17/9/2018 | 17/6/2026 | Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing… | |
| Modificada | Media (6.6) | 1.2% | — | SAP Hana Extended Application Services | 14/8/2018 | 17/6/2026 | XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been… | |
| Modificada | Media (6.5) | 0.73% | — | Pivotal Software Pivotal Application Service | 24/7/2018 | 17/6/2026 | Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to… | |
| Modificada | Media (6.7) | 0.39% | — | Cisco Wide Area Application Services | 7/6/2018 | 17/6/2026 | A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privilege level to root. The attacker must have valid user credentials with super user privileges (level 15) to log in to the device. The… | |
| Modificada | Media (5.3) | 2.4% | — | Cisco Wide Area Application Services | 7/6/2018 | 17/6/2026 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to a hard-coded, read-only community… | |
| Modificada | Media (6.5) | 1.2% | — | Pivotal Software Pivotal Application Service | 11/5/2018 | 17/6/2026 | Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation… | |
| Modificada | Media (6.5) | 1.3% | — | Pivotal Software Pivotal Application Service | 16/3/2018 | 17/6/2026 | Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links. | |
| Modificada | Media (6.5) | 0.89% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. | |
| Modificada | Media (6.5) | 1.2% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Hana Extended Application Services | 12/12/2017 | 17/6/2026 | Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could allow unprivileged attackers to forge audit log lines. Hence the interpretation of audit log files could be hindered or… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Virtual Wide Area Application ServicesCisco Wide Area Application Services | 5/10/2017 | 17/6/2026 | A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an ICA application optimization-related process to restart, resulting in a partial denial of service (DoS) condition. The… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Wide Area Application Services | 5/10/2017 | 17/6/2026 | A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability is due to certain file-handling inefficiencies of the affected system. An… | |
| Modificada | Media (5.3) | 3.1% | — | Cisco Wide Area Application Services | 21/9/2017 | 17/6/2026 | A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition. The vulnerability is due to lack of input validation… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Wide Area Application Services | 10/7/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker to retrieve completed reports from an affected system, aka Information Disclosure. This vulnerability affects the following products if they are running an affected… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Wide Area Application Services | 10/7/2017 | 17/6/2026 | A vulnerability in the Server Message Block (SMB) protocol of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device due to a process restarting unexpectedly and creating Core Dump files. More Information:… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Wide Area Application Services | 4/7/2017 | 17/6/2026 | A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases:… |