Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.43% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 28/7/2026 | 28/7/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their… | |
| Aplazada | Alta (8.4) | 0.95% | — | SAP Application Server FOR AbapAISAP Netweaver RfcsdkAI | 13/1/2026 | 17/6/2026 | Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary… | |
| Aplazada | Baja (2.7) | 0.25% | — | SAP Netweaver Application Server FOR AbapAISAP Migration WorkbenchAISAP DX WorkbenchAI | 11/11/2025 | 17/6/2026 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files to the application server. An attacker could leverage this and upload a malicious file into the system. This results in a low impact on the… | |
| Aplazada | Media (5.4) | 0.16% | — | SAP Netweaver Application Server FOR AbapAI | 14/10/2025 | 17/6/2026 | Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to… | |
| Aplazada | Media (5.4) | 0.23% | — | SAP Application Server FOR AbapAI | 14/10/2025 | 17/6/2026 | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application. | |
| Aplazada | Media (4.9) | 0.33% | — | SAP Netweaver Application Server FOR AbapAI | 8/7/2025 | 17/6/2026 | Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations, unauthorized reading of critical data… | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 14/1/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high… | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 10/12/2024 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied… | |
| Aplazada | Media (5.3) | 3.5% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 12/11/2024 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable.… | |
| Aplazada | Media (6.1) | 0.27% | — | SAP Netweaver Application Server FOR AbapAI | 10/9/2024 | 17/6/2026 | Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the… |