Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.40% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information. | |
| Modificada | Media (6.1) | 0.37% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to… | |
| Modificada | Media (5.4) | 0.46% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (6.1) | 0.35% | — | SAP Netweaver Application Server Abap | 14/2/2023 | 17/6/2026 | An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some… | |
| Modificada | Crítica (9.8) | 16% | — | SAP Netweaver Application Server FOR Java | 10/1/2023 | 17/6/2026 | An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could… | |
| Modificada | Crítica (9.8) | 0.69% | — | SAP Netweaver Application Server AbapSAP Netweaver Application Server Abap KernelSAP Netweaver Application Server Abap Krnl64nucSAP Netweaver Application Server Abap Krnl64uc | 10/1/2023 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver Application Server Abap | 10/1/2023 | 17/6/2026 | The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause… | |
| Modificada | Alta (8.6) | 1.0% | 💥 PoC | SAP Netweaver Process Integration | 13/12/2022 | 17/6/2026 | An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting… | |
| Modificada | Crítica (9.4) | 0.59% | — | SAP Netweaver Process Integration | 13/12/2022 | 17/6/2026 | An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users… | |
| Modificada | Media (6.1) | 0.45% | — | SAP Netweaver Application Server Java | 12/12/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of… | |
| Modificada | Media (4.7) | 0.46% | — | SAP Netweaver Application Server Abap | 8/11/2022 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information. | |
| Modificada | Alta (8.7) | 0.80% | — | SAP Netweaver Application Server Abap | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to delete a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the integrity and availability of… | |
| Modificada | Media (4.9) | 0.82% | — | SAP Netweaver Application Server Abap | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the… | |
| Modificada | Media (6.1) | 0.53% | — | SAP Netweaver Application Server Abap | 13/9/2022 | 17/6/2026 | An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user. | |
| Modificada | Media (6.1) | 0.54% | — | SAP Netweaver Enterprise Portal | 13/9/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of… | |
| Modificada | Media (5.4) | 0.51% | — | SAP Netweaver Application Server Abap | 13/9/2022 | 17/6/2026 | An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information… | |
| Modificada | Media (6.1) | 0.73% | — | SAP Netweaver Enterprise Portal | 12/7/2022 | 17/6/2026 | A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script code which could lead to stealing or… | |
| Modificada | Media (6.1) | 0.61% | — | SAP Netweaver Enterprise Portal | 12/7/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and… | |
| Modificada | Media (6.1) | 0.61% | — | SAP Netweaver Enterprise Portal | 12/7/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.61% | — | SAP Netweaver Enterprise Portal | 12/7/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and… | |
| Modificada | Media (6.1) | 0.85% | — | SAP Netweaver Enterprise Portal | 12/7/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing… | |
| Modificada | Media (6.1) | 1.1% | — | SAP Netweaver Development Infrastructure | 14/6/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information… | |
| Modificada | Baja (3.4) | 0.24% | — | SAP Netweaver Developer Studio | 14/6/2022 | 17/6/2026 | SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x. | |
| Modificada | Media (5) | 0.44% | — | SAP Host AgentSAP Netweaver Abap | 14/6/2022 | 17/6/2026 | SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, - on Unix systems, s-bit helper program… | |
| Modificada | Media (4.3) | 0.66% | — | SAP Host AgentSAP Netweaver Abap | 14/6/2022 | 17/6/2026 | SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in… |