Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 0.90% | — | SAP Netweaver Application Server Java | 12/2/2020 | 17/6/2026 | Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure. | |
| Modificada | Media (4.3) | 0.89% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Netweaver Application Server Java | 13/11/2019 | 17/6/2026 | An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise. | |
| Modificada | Alta (7.2) | 1.6% | — | SAP Netweaver Application Server Java | 10/9/2019 | 17/6/2026 | SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application. | |
| Modificada | Crítica (9.8) | 2.3% | — | SAP Netweaver Application Server Java | 14/8/2019 | 17/6/2026 | A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console,… | |
| Modificada | Alta (7.2) | 2.1% | — | SAP Netweaver Application Server Java | 10/7/2019 | 17/6/2026 | SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation. | |
| Modificada | Media (5.3) | 1.4% | — | SAP Netweaver Application Server Java | 10/7/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Media (5.4) | 0.78% | — | SAP Netweaver Application Server Java | 12/3/2019 | 17/6/2026 | SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.1% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50. | |
| Modificada | Alta (7.4) | 0.57% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50). | |
| Modificada | Alta (7.1) | 1.1% | — | SAP Netweaver Application Server Java | 11/12/2018 | 17/6/2026 | SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50. | |
| Modificada | Media (6.1) | 1.4% | — | SAP Netweaver Application Server Java | 11/9/2018 | 17/6/2026 | The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Netweaver Application Server Java | 19/9/2017 | 17/6/2026 | The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181. | |
| Analizada | Alta (7.5) | 95% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 7/8/2017 | 17/6/2026 | Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657. | |
| Modificada | Media (6.1) | 0.97% | — | SAP Netweaver Application Server Java | 25/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783. | |
| Modificada | Media (6.5) | 1.4% | — | SAP Netweaver Application Server Java | 25/7/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249. | |
| Modificada | Alta (8.8) | 1.4% | — | SAP Netweaver Application Server Java | 23/5/2017 | 17/6/2026 | The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873. | |
| Modificada | Alta (8.8) | 1.9% | — | SAP Netweaver Application Server Java | 14/4/2017 | 17/6/2026 | SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504. | |
| Modificada | Media (6.5) | 1.6% | — | SAP Netweaver Application Server Java | 10/4/2017 | 17/6/2026 | The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788. | |
| Analizada | Media (6.5) | 24% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 23/11/2016 | 17/6/2026 | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909. | |
| Modificada | Alta (7.5) | 4.0% | — | SAP Netweaver Application Server Java | 23/11/2016 | 17/6/2026 | SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835. | |
| Analizada | Crítica (10) | 18% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 13/5/2016 | 16/6/2026 | The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Netweaver Application Server Java | 8/4/2016 | 17/6/2026 | The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or… | |
| Analizada | Alta (7.5) | 47% | ⚠ Explotación activa | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971. | |
| Modificada | Media (6.1) | 1.6% | — | SAP Netweaver Application Server Java | 7/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note… |