Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

491 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)3.5%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI12/11/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable.…
AplazadaMedia (6.5)0.27%—SAP Netweaver AS JavaAI12/11/202417/6/2026
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
AnalizadaMedia (5.4)0.26%—SAP Netweaver Enterprise Portal8/10/202417/6/2026
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking it. When a victim who is registered on the portal clicks on such link, confidentiality and…
AplazadaMedia (6)0.17%—SAP Netweaver AS FOR JavaAI10/9/202417/6/2026
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
AplazadaMedia (4.8)0.24%—SAP Netweaver AS JavaAI10/9/202417/6/2026
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
AplazadaMedia (6.1)0.27%—SAP Netweaver Application Server FOR AbapAI10/9/202417/6/2026
Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the…
AplazadaMedia (4.7)0.25%—SAP Netweaver Enterprise PortalAI10/9/202417/6/2026
SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and…
AnalizadaBaja (2.7)0.29%—SAP Netweaver Application Server Abap10/9/202417/6/2026
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view these objects.
AplazadaMedia (4.3)0.25%—SAP NetweaverAI10/9/202417/6/2026
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
AnalizadaBaja (2.7)0.26%—SAP Netweaver Application Server Abap10/9/202417/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.
AnalizadaMedia (4.3)0.26%—SAP Netweaver Application Server Abap13/8/202417/6/2026
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
AnalizadaMedia (5.4)0.32%—SAP Netweaver Application Server Abap13/8/202417/6/2026
—
AnalizadaMedia (6.3)0.21%—SAP Netweaver AbapSAP Netweaver JavaSAP Content ServerSAP WEB Dispatcher13/8/202417/6/2026
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the…
ModificadaMedia (6.1)0.26%—SAP Netweaver Knowledge Management AND Collaboration (kmc-cm)9/7/202417/6/2026
Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its…
ModificadaAlta (7.5)0.54%—SAP Netweaver Application Server Java11/6/202417/6/2026
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.
ModificadaMedia (6.5)0.41%—SAP Netweaver Application Server Abap11/6/202417/6/2026
SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial of Service vulnerability might be long response delays and service interruptions, thus degrading the service quality experienced by legitimate users causing high…
ModificadaMedia (5.3)0.33%—SAP Netweaver Application Server Java11/6/202417/6/2026
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.
AplazadaMedia (6.1)0.40%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI14/5/202417/6/2026
Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information…
AplazadaMedia (6.5)0.53%—SAP NetweaverAISAP Abap PlatformAI9/4/202417/6/2026
The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. This leads to a considerable impact on availability.
AplazadaAlta (8.8)0.40%—SAP Netweaver AS JavaAI9/4/202417/6/2026
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and…
AnalizadaMedia (5.3)0.45%—SAP Netweaver9/4/202417/6/2026
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability.…
AnalizadaMedia (5.3)0.45%—SAP Netweaver Process Integration12/3/202417/6/2026
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
AnalizadaMedia (6.1)0.47%—SAP Netweaver AS Abap12/3/202417/6/2026
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s…
AnalizadaMedia (5.3)0.41%—SAP Netweaver Enterprise Portal12/3/202417/6/2026
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
AnalizadaMedia (5.3)0.41%—SAP Netweaver12/3/202417/6/2026
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
Orbitaley — Vulnerabilidades