Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
491 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.2% | — | SAP Netweaver AS AbapSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64ucSAP Router | 14/6/2022 | 17/6/2026 | Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions KERNEL 7.49, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.49, KRNL64UC 7.49, SAP_ROUTER 7.53,… | |
| Modificada | Media (6.5) | 0.74% | — | SAP Netweaver | 13/6/2022 | 17/6/2026 | Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash. | |
| Modificada | Alta (7.5) | 0.96% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64nucSAP Netweaver AS Abap Krnl64uc | 11/5/2022 | 17/6/2026 | SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption. | |
| Modificada | Alta (8.8) | 0.80% | — | SAP Netweaver Application Server Abap | 11/5/2022 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (5.4) | 0.46% | — | SAP Netweaver Application Server Abap | 11/5/2022 | 17/6/2026 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack. | |
| Modificada | Media (6.1) | 0.57% | — | SAP Netweaver AS Abap KernelSAP Netweaver AS Abap Krnl64ucSAP Webdispatcher | 11/5/2022 | 17/6/2026 | The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.5% | — | SAP NetweaverSAP WEB Dispatcher | 12/4/2022 | 17/6/2026 | Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP NetweaverSAP WEB Dispatcher | 12/4/2022 | 17/6/2026 | By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which… | |
| Modificada | Media (4.7) | 0.82% | — | SAP Netweaver Abap | 12/4/2022 | 17/6/2026 | SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information. | |
| Modificada | Alta (7.5) | 1.0% | — | SAP Netweaver Application Server FOR Java | 12/4/2022 | 17/6/2026 | An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges. | |
| Modificada | Media (6.1) | 0.91% | — | SAP Netweaver Enterprise Portal | 12/4/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing… | |
| Modificada | Media (5.3) | 0.77% | — | SAP Netweaver Application Server Java | 10/3/2022 | 17/6/2026 | Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks. | |
| Modificada | Media (5.4) | 0.49% | — | SAP Netweaver Application Server Abap | 10/3/2022 | 17/6/2026 | Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized for that transaction. A successful… | |
| Modificada | Media (6.1) | 0.83% | — | SAP Netweaver Enterprise Portal | 10/3/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The… | |
| Modificada | Media (6.1) | 0.61% | — | SAP Netweaver Enterprise Portal | 10/3/2022 | 17/6/2026 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (4.9) | 0.82% | — | SAP Netweaver Abap | 9/2/2022 | 17/6/2026 | A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWeaver Application Server ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Netweaver AbapSAP Netweaver AS Abap | 9/2/2022 | 17/6/2026 | SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.49, does not sufficiently validate sap-passport information, which could lead to a Denial-of-Service… | |
| Modificada | Alta (7.5) | 1.2% | — | SAP Netweaver Application Server Abap | 9/2/2022 | 17/6/2026 | SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of… | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | SAP Content ServerSAP Netweaver Application Server AbapSAP WEB Dispatcher | 9/2/2022 | 17/6/2026 | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute… | |
| Modificada | Media (6.1) | 0.83% | — | SAP Netweaver | 9/2/2022 | 17/6/2026 | Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application. | |
| Modificada | Alta (7.5) | 1.8% | — | SAP Netweaver Application Server Java | 9/2/2022 | 17/6/2026 | Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in… | |
| Modificada | Crítica (9.8) | 2.4% | — | SAP Netweaver Application Server Java | 9/2/2022 | 17/6/2026 | In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be… | |
| Modificada | Media (4.3) | 0.63% | — | SAP Netweaver AbapSAP Netweaver Application Server Abap | 14/1/2022 | 17/6/2026 | In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial… | |
| Modificada | Media (6.7) | 0.30% | — | SAP Netweaver Application Server Abap | 14/12/2021 | 17/6/2026 | Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of… | |
| Modificada | Crítica (9.8) | 1.4% | — | SAP Abap PlatformSAP Netweaver Application Server Abap | 14/12/2021 | 17/6/2026 | Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |