Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

491 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.22%—SAP Netweaver Abap PlatformAI9/9/202517/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the…
AplazadaBaja (3.4)0.14%—SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI9/9/202517/6/2026
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on…
AnalizadaMedia (5.3)0.30%—SAP Netweaver Application Server Java9/9/202517/6/2026
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This…
AplazadaMedia (4.3)0.24%—SAP Netweaver AS JavaAI9/9/202517/6/2026
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of several identifiers generated close to the same time, the attacker could…
AplazadaCrítica (9.9)0.72%—SAP Netweaver AS JavaAI9/9/202517/6/2026
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.
AplazadaAlta (8.1)0.42%—SAP Netweaver Application Server AbapAI12/8/202517/6/2026
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target…
AplazadaMedia (6.1)0.26%—SAP Netweaver Application Server AbapAISAP BIC DocumentAI12/8/202517/6/2026
SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify…
AplazadaMedia (6.1)0.23%—SAP Netweaver Abap PlatformAI12/8/202517/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of…
AplazadaMedia (6.1)0.21%—SAP Netweaver Application Server AbapAI12/8/202517/6/2026
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There…
AplazadaMedia (6.1)0.23%—SAP Netweaver Application Server AbapAI12/8/202517/6/2026
SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify…
AplazadaMedia (4.1)0.13%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI12/8/202517/6/2026
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no…
AplazadaMedia (6.1)0.23%—SAP Netweaver Application Server AbapAI8/7/202517/6/2026
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled…
AplazadaCrítica (9.1)0.76%—SAP Netweaver Enterprise PortalAI8/7/202517/6/2026
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
AplazadaBaja (3.5)0.14%—SAP Netweaver Application Server JavaAI8/7/202517/6/2026
The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being…
AplazadaMedia (6.1)0.23%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI8/7/202517/6/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can…
AnalizadaMedia (4.3)0.26%—SAP Netweaver8/7/202517/6/2026
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on…
AplazadaCrítica (9.1)0.72%—SAP NetweaverAI8/7/202517/6/2026
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact on confidentiality, integrity, and availability of the application.
AplazadaCrítica (9.1)0.72%—SAP Netweaver Enterprise PortalAI8/7/202517/6/2026
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
AplazadaCrítica (9.1)0.74%—SAP Netweaver Application Server FOR JavaAI8/7/202517/6/2026
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting attackers complete control over the affected system. This results in a…
AplazadaMedia (4.9)0.33%—SAP Netweaver Application Server FOR AbapAI8/7/202517/6/2026
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized reading of critical data…
AplazadaBaja (2.7)0.43%—SAP Netweaver Business WarehouseAISAP CcawAI8/7/202517/6/2026
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the…
AplazadaAlta (8.1)0.47%—SAP NetweaverAI8/7/202517/6/2026
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.
AplazadaAlta (7.6)0.59%—SAP Netweaver Visual ComposerAI10/6/202517/6/2026
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity.
AplazadaMedia (5.8)0.31%—SAP NetweaverAI10/6/202517/6/2026
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the script executes in their browser, providing the attacker limited…
AnalizadaCrítica (9.1)14%⚠ Explotación activaSAP Netweaver13/5/202511/8/2026
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
Orbitaley — Vulnerabilidades