Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

491 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5)0.28%—SAP Netweaver Application Server Abap10/3/202617/6/2026
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their…
Pendiente de análisisCrítica (9.1)0.57%—SAP Netweaver Enterprise PortalAI10/3/202617/6/2026
SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.
Pendiente de análisisMedia (6.4)0.33%—SAP NetweaverAI10/3/202617/6/2026
SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacker to inject arbitrary SQL code through user-controlled input fields. The application concatenates these inputs directly into SQL queries without proper validation or escaping. As a result, an…
AnalizadaMedia (6.4)0.16%—SAP Netweaver Application Server Abap10/3/202617/6/2026
SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with potentially sensitive…
AnalizadaMedia (4.3)0.19%—SAP Netweaver Application Server Abap10/3/202617/6/2026
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on…
AnalizadaMedia (6.4)0.21%—SAP Netweaver Application Server Abap10/3/202617/6/2026
Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or…
AnalizadaBaja (3.1)0.25%—SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc10/2/202617/6/2026
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the…
AnalizadaBaja (3.4)0.17%—SAP Netweaver Application Server Java10/2/202617/6/2026
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing…
AnalizadaMedia (4.4)0.13%—SAP Netweaver10/2/202617/6/2026
Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially…
AnalizadaCrítica (9.6)0.36%—SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc10/2/202617/6/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the…
AnalizadaCrítica (9.9)0.52%—SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework10/2/202617/6/2026
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on…
AplazadaBaja (3)0.14%—SAP Netweaver Application Server JavaAI13/1/202617/6/2026
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial…
AplazadaAlta (8.4)0.95%—SAP Application Server FOR AbapAISAP Netweaver RfcsdkAI13/1/202617/6/2026
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary…
AnalizadaAlta (8.1)0.26%—SAP Netweaver Application Server Abap13/1/202617/6/2026
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system…
AplazadaMedia (6.1)0.20%—SAP Netweaver Enterprise PortalAI13/1/202617/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user…
AplazadaMedia (6.1)0.26%—SAP Netweaver Enterprise PortalAI9/12/202517/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability…
AplazadaAlta (7.9)0.47%—SAP NetweaverAISAP XcelsiusAI9/12/202530/9/2026
SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or…
AplazadaMedia (5.3)0.46%—SAP Netweaver Application Server JavaAI11/11/202517/6/2026
Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive…
AplazadaMedia (6.5)0.26%—SAP Netweaver Enterprise PortalAI11/11/202517/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modification of information about the server. There is no impact on…
AplazadaBaja (2.7)0.25%—SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI11/11/202517/6/2026
Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the…
AplazadaMedia (4.3)0.23%—SAP Netweaver Application Server AbapAI11/11/202517/6/2026
Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist…
AplazadaMedia (5.4)0.16%—SAP Netweaver Application Server FOR AbapAI14/10/202517/6/2026
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to…
AplazadaMedia (5.3)0.37%—SAP Netweaver AS AbapAISAP Abap PlatformAI14/10/202517/6/2026
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the…
AplazadaCrítica (9.1)0.69%—SAP NetweaverAIIBM I-seriesAI9/9/202517/6/2026
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality,…
AplazadaCrítica (10)2.9%💥 PoCSAP NetweaverAI9/9/202517/6/2026
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the…
Orbitaley — Vulnerabilidades