Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2261 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.18%—SAP Solution Tools Plug-in10/2/202617/6/2026
In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted.
AnalizadaAlta (7.5)0.42%—SAP Businessobjects Business Intelligence Platform10/2/202617/6/2026
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatically restart. By repeatedly submitting these requests, the attacker could induce a persistent service disruption, rendering the CMS completely…
AnalizadaMedia (6.5)0.29%—SAP Basis10/2/202617/6/2026
Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and…
AplazadaMedia (4.3)0.20%—SAP Fiori APP Intercompany Balance ReconciliationAI27/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.
AnalizadaMedia (6.1)0.20%—SAP Business Connector13/1/202617/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify…
AnalizadaMedia (4.7)0.20%—SAP Supplier Relationship Management13/1/202617/6/2026
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site.This causes low impact on integrity of the application. Confidentiality and…
AplazadaAlta (8.1)0.30%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
AplazadaBaja (3)0.14%—SAP Netweaver Application Server JavaAI13/1/202617/6/2026
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial…
AplazadaAlta (8.4)0.95%—SAP Application Server FOR AbapAISAP Netweaver RfcsdkAI13/1/202617/6/2026
Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary…
AnalizadaAlta (8.1)0.26%—SAP Netweaver Application Server Abap13/1/202617/6/2026
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system…
AplazadaBaja (3.8)0.19%—SAP Identity ManagementAI13/1/202617/6/2026
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in…
AplazadaMedia (6.4)0.23%—SAP ERP Central ComponentAISAP EHS ManagementAISAP S/4hanaAI13/1/202617/6/2026
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or…
AplazadaCrítica (9.9)0.47%—SAP S/4hanaAI13/1/202617/6/2026
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.
AnalizadaAlta (8.8)0.41%—SAP Introscope Enterprise Manager13/1/202617/6/2026
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could…
AplazadaMedia (6.1)0.20%—SAP Netweaver Enterprise PortalAI13/1/202617/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user…
AnalizadaAlta (7.2)0.47%—SAP S/4 Hana13/1/202617/6/2026
SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions…
AplazadaMedia (4.3)0.22%—SAP Product Designer WEB UIAISAP Business Server PagesAI13/1/202617/6/2026
SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.
AplazadaMedia (6.6)0.22%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
AplazadaMedia (5.1)0.18%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
AplazadaMedia (4.3)0.21%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.
AplazadaMedia (4.3)0.13%—SAP Fiori APP Intercompany Balance ReconciliationAI13/1/202617/6/2026
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an…
AnalizadaAlta (8.8)0.33%—SAP Hana Database13/1/202617/6/2026
SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and availability.
AplazadaCrítica (9.1)0.51%—SAP Landscape TransformationAI13/1/202617/6/2026
SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,…
AplazadaCrítica (9.1)9.5%—SAP JconnectAI9/12/20257/10/2026
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch remote code execution. The system may be vulnerable when specially crafted input is used to exploit the vulnerability resulting in high impact on confidentiality, integrity and availability of the…
AplazadaMedia (6.5)0.33%—SAP Application Server AbapAI9/12/20257/10/2026
Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.