Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 3.0% | — | SAP AS Abap(dmis)SAP S4 Hana(dmis) | 10/11/2020 | 17/6/2026 | SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the… | |
| Modificada | Media (6.5) | 1.0% | — | SAP Bank AnalyzerSAP S/4hana FOR Financial Products Subledger | 9/9/2020 | 17/6/2026 | Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system administrator to create incorrect… | |
| Modificada | Media (4.3) | 0.56% | — | SAP S/4 Hana Fiori UI FOR General Ledger Accounting | 12/8/2020 | 17/6/2026 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check. | |
| Modificada | Media (5.4) | 0.65% | — | SAP ERPSAP S/4hana | 24/4/2020 | 17/6/2026 | Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax… | |
| Modificada | Media (4.3) | 0.74% | — | Banking Services From SAPSAP S/4hana Financial Products Subledger | 14/4/2020 | 17/6/2026 | SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system. | |
| Modificada | Media (4.7) | 0.65% | — | SAP S/4hana | 14/4/2020 | 17/6/2026 | SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the… | |
| Modificada | Alta (8.8) | 0.68% | — | SAP ERPSAP S/4 Hana | 12/2/2020 | 17/6/2026 | VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check. | |
| Modificada | Media (5.4) | 0.54% | — | SAP NetweaverSAP S/4hana | 12/2/2020 | 17/6/2026 | Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability. | |
| Modificada | Media (6.1) | 0.96% | — | SAP NetweaverSAP S/4hana | 12/2/2020 | 17/6/2026 | Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.3) | 0.74% | — | SAP ERP SalesSAP S4hana Sales | 13/11/2019 | 17/6/2026 | Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP Hana Database | 4/11/2019 | 17/6/2026 | SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service | |
| Modificada | Media (4.3) | 0.70% | — | SAP Hana Extended Application Services | 10/9/2019 | 17/6/2026 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports. | |
| Modificada | Alta (7.1) | 0.90% | — | SAP Hana Extended Application Services | 10/9/2019 | 17/6/2026 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports. | |
| Modificada | Media (6.7) | 0.39% | — | SAP Hana | 10/9/2019 | 17/6/2026 | The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges. | |
| Modificada | Media (4.3) | 0.88% | — | SAP Hana Extended Application Services | 12/6/2019 | 17/6/2026 | SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names. | |
| Modificada | Media (6) | 0.35% | — | SAP Hana | 10/4/2019 | 17/6/2026 | SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary… | |
| Modificada | Media (6.1) | 1.3% | — | Khanacademy Simple-markdownFedoraproject Fedora | 9/4/2019 | 17/6/2026 | simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. | |
| Modificada | Media (6.5) | 2.1% | — | SAP Hana Extended Application Services | 12/3/2019 | 17/6/2026 | SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). | |
| Modificada | Alta (8.8) | 1.7% | — | Banking Services From SAPSAP S/4hana Financial Products Subledger | 12/3/2019 | 17/6/2026 | Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation of privileges. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 PoC | Kohanaframework Kohana | 21/2/2019 | 17/6/2026 | Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. | |
| Modificada | Alta (7.5) | 1.8% | — | SAP Hana Extended Application Services | 15/2/2019 | 17/6/2026 | Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased. | |
| Modificada | Alta (8.8) | 1.7% | — | SAP Bw/4hana | 8/1/2019 | 17/6/2026 | Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (6.1) | 1.3% | — | SAP Business ONE ON Hana | 11/12/2018 | 17/6/2026 | TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3). | |
| Modificada | Baja (2.7) | 0.93% | — | SAP Hana | 11/12/2018 | 17/6/2026 | The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT. | |
| Modificada | Alta (7.5) | 2.6% | — | SAP Hana | 11/9/2018 | 17/6/2026 | SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash. |