Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

491 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.2%—SAP Netweaver AS AbapSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64ucSAP Router14/6/202217/6/2026
Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53,…
ModificadaMedia (6.5)0.74%—SAP Netweaver13/6/202217/6/2026
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
ModificadaAlta (7.5)0.96%—SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc11/5/202217/6/2026
SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.
ModificadaAlta (8.8)0.80%—SAP Netweaver Application Server Abap11/5/202217/6/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
ModificadaMedia (5.4)0.46%—SAP Netweaver Application Server Abap11/5/202217/6/2026
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
ModificadaMedia (6.1)0.57%—SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64ucSAP Webdispatcher11/5/202217/6/2026
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaAlta (7.5)1.5%—SAP NetweaverSAP WEB Dispatcher12/4/202217/6/2026
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.
ModificadaAlta (7.5)1.4%—SAP NetweaverSAP WEB Dispatcher12/4/202217/6/2026
By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which…
ModificadaMedia (4.7)0.82%—SAP Netweaver Abap12/4/202217/6/2026
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.
ModificadaAlta (7.5)1.0%—SAP Netweaver Application Server FOR Java12/4/202217/6/2026
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
ModificadaMedia (6.1)0.91%—SAP Netweaver Enterprise Portal12/4/202217/6/2026
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing…
ModificadaMedia (5.3)0.77%—SAP Netweaver Application Server Java10/3/202217/6/2026
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
ModificadaMedia (5.4)0.49%—SAP Netweaver Application Server Abap10/3/202217/6/2026
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized for that transaction. A successful…
ModificadaMedia (6.1)0.83%—SAP Netweaver Enterprise Portal10/3/202217/6/2026
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The…
ModificadaMedia (6.1)0.61%—SAP Netweaver Enterprise Portal10/3/202217/6/2026
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (4.9)0.82%—SAP Netweaver Abap9/2/202217/6/2026
A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756.
ModificadaAlta (7.5)1.4%—SAP Netweaver AbapSAP Netweaver AS Abap9/2/202217/6/2026
SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service…
ModificadaAlta (7.5)1.2%—SAP Netweaver Application Server Abap9/2/202217/6/2026
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of…
AnalizadaCrítica (10)98%⚠ Explotación activa💥 ExploitSAP Content ServerSAP Netweaver Application Server AbapSAP WEB Dispatcher9/2/202217/6/2026
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute…
ModificadaMedia (6.1)0.83%—SAP Netweaver9/2/202217/6/2026
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
ModificadaAlta (7.5)1.8%—SAP Netweaver Application Server Java9/2/202217/6/2026
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in…
ModificadaCrítica (9.8)2.4%—SAP Netweaver Application Server Java9/2/202217/6/2026
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be…
ModificadaMedia (4.3)0.63%—SAP Netweaver AbapSAP Netweaver Application Server Abap14/1/202217/6/2026
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial…
ModificadaMedia (6.7)0.30%—SAP Netweaver Application Server Abap14/12/202117/6/2026
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of…
ModificadaCrítica (9.8)1.4%—SAP Abap PlatformSAP Netweaver Application Server Abap14/12/202117/6/2026
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.