Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.25% | — | SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI | 11/11/2025 | 17/6/2026 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the… | |
| Aplazada | Media (4.3) | 0.23% | — | SAP Netweaver Application Server AbapAI | 11/11/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist… | |
| Aplazada | Media (5.4) | 0.16% | — | SAP Netweaver Application Server FOR AbapAI | 14/10/2025 | 17/6/2026 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to… | |
| Analizada | Media (5.3) | 0.30% | — | SAP Netweaver Application Server Java | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This… | |
| Aplazada | Alta (8.1) | 0.42% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target… | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Netweaver Application Server AbapAISAP BIC DocumentAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify… | |
| Aplazada | Media (6.1) | 0.21% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify… | |
| Aplazada | Media (4.1) | 0.13% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 12/8/2025 | 17/6/2026 | The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAI | 8/7/2025 | 17/6/2026 | Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled… | |
| Aplazada | Baja (3.5) | 0.14% | — | SAP Netweaver Application Server JavaAI | 8/7/2025 | 17/6/2026 | The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being… | |
| Aplazada | Media (6.1) | 0.23% | — | SAP Netweaver Application Server AbapAISAP Abap PlatformAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can… | |
| Aplazada | Crítica (9.1) | 0.74% | — | SAP Netweaver Application Server FOR JavaAI | 8/7/2025 | 17/6/2026 | A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a… | |
| Aplazada | Media (4.9) | 0.33% | — | SAP Netweaver Application Server FOR AbapAI | 8/7/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized reading of critical data… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and… | |
| Aplazada | Media (4.7) | 0.24% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script… | |
| Aplazada | Alta (8.5) | 0.50% | — | SAP Netweaver Application Server AbapAI | 8/4/2025 | 17/6/2026 | In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote… | |
| Aplazada | Media (5.4) | 0.22% | — | SAP Netweaver Application Server JavaAI | 11/3/2025 | 17/6/2026 | User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data… | |
| Aplazada | Media (6.1) | 0.24% | — | SAP Netweaver Application Server AbapAI | 11/3/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript… | |
| Aplazada | Media (6.1) | 0.25% | — | SAP Netweaver Application Server AbapAI | 11/3/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely… | |
| Aplazada | Media (5.4) | 0.27% | 💥 PoC | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the… | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 14/1/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Netweaver Application Server AbapAI | 14/1/2025 | 17/6/2026 | An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application. | |
| Aplazada | Media (6.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 14/1/2025 | 17/6/2026 | Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and… |