Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 1.2% | — | SAP Hana Extended Application Services | 14/8/2018 | 17/6/2026 | XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been… | |
| Modificada | Alta (7.5) | 1.1% | — | Betterthanadrien Project Betterthanadrien | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for BetterThanAdrien, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 2.4% | — | SAP Hana DatabaseSAP UISAP UI5SAP UI5 Java | 12/6/2018 | 17/6/2026 | SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40,… | |
| Modificada | Alta (8.4) | 1.5% | — | SAP Hana | 14/3/2018 | 17/6/2026 | In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control… | |
| Modificada | Media (6.5) | 0.89% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. | |
| Modificada | Media (6.5) | 1.2% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. | |
| Modificada | Alta (7.5) | 1.1% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. | |
| Modificada | Media (5.3) | 1.5% | — | SAP Hana | 14/2/2018 | 17/6/2026 | Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or… | |
| Modificada | Media (5.3) | 1.6% | — | SAP Hana | 9/1/2018 | 17/6/2026 | A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname. | |
| Modificada | Media (5.3) | 1.3% | — | SAP Hana Database | 12/12/2017 | 17/6/2026 | The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Hana Extended Application Services | 12/12/2017 | 17/6/2026 | Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could allow unprivileged attackers to forge audit log lines. Hence the interpretation of audit log files could be hindered or… | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | CodeigniterKohanaframework Kohana | 19/9/2017 | 17/6/2026 | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes. | |
| Modificada | Media (6.1) | 1.7% | — | Kohanaframework KohanaDebian Linux | 31/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php. | |
| Modificada | Media (5.4) | 0.91% | — | Osisoft PI Integrator FOR Business AnalysticsOsisoft PI Integrator FOR Microsoft AzureOsisoft PI Integrator FOR SAP Hana | 14/8/2017 | 17/6/2026 | A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker may be able to upload a malicious script that attempts to redirect users to a malicious web site. | |
| Modificada | Crítica (9.8) | 2.3% | — | Osisoft PI Integrator FOR Business AnalysticsOsisoft PI Integrator FOR Microsoft AzureOsisoft PI Integrator FOR SAP Hana | 14/8/2017 | 17/6/2026 | An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker is able to gain privileged access to the system while unauthorized. | |
| Modificada | Alta (7.5) | 2.6% | — | SAP Hana XS | 23/5/2017 | 17/6/2026 | sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694. | |
| Modificada | Alta (8.3) | 1.5% | — | SAP Hana XS | 23/5/2017 | 17/6/2026 | sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694. | |
| Modificada | Alta (7.8) | 1.2% | — | Justsystems HanakoJustsystems Hanako PoliceJustsystems Hanako PROJustsystems Just Frontier+5 | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017… | |
| Modificada | Crítica (9.8) | 3.6% | — | SAP Hana | 13/4/2017 | 17/6/2026 | SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. | |
| Modificada | Alta (7.5) | 2.9% | — | SAP Hana | 26/9/2016 | 17/6/2026 | SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459. |