Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.75% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information. | |
| Modificada | Media (6.5) | 0.48% | — | SAP Netweaver Application Server Abap | 8/8/2023 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 793, SAP_BASIS 804, does not perform necessary… | |
| Modificada | Alta (7.4) | 0.39% | — | SAP Netweaver Application Server Abap | 11/7/2023 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 11/7/2023 | 17/6/2026 | SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability. | |
| Modificada | Crítica (9.1) | 0.62% | — | SAP Netweaver Application Server FOR Java | 9/5/2023 | 17/6/2026 | In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication. A… | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 11/4/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any… | |
| Modificada | Media (6.1) | 0.45% | — | SAP NetweaverSAP Netweaver Application Server Abap | 11/4/2023 | 17/6/2026 | SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to… | |
| Modificada | Crítica (9.6) | 0.97% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this… | |
| Modificada | Alta (8.1) | 0.98% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable. | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will… | |
| Modificada | Crítica (9.6) | 0.98% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files. In this attack, no data can… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and… | |
| Modificada | Media (5.3) | 0.48% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity | |
| Modificada | Alta (7.4) | 0.37% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which… | |
| Modificada | Media (6.5) | 0.61% | — | SAP Netweaver Application Server Abap | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters… | |
| Modificada | Media (5.3) | 0.58% | — | SAP Netweaver Application Server Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive… | |
| Modificada | Alta (8.6) | 0.54% | — | SAP Netweaver Application Server FOR Java | 14/3/2023 | 17/6/2026 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose… | |
| Modificada | Media (6.1) | 0.40% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information. | |
| Modificada | Media (6.1) | 0.37% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to… | |
| Modificada | Media (5.4) | 0.46% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (6.1) | 0.35% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some… | |
| Modificada | Crítica (9.8) | 16% | — | SAP Netweaver Application Server FOR Java | 10/1/2023 | 17/6/2026 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could… |