Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.2) | 0.18% | — | SAP Basis | 10/2/2026 | 17/6/2026 | An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact… | |
| Modificada | Alta (8.8) | 0.49% | — | SAP Basis | 10/2/2026 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and… | |
| Analizada | Media (6.5) | 0.29% | — | SAP Basis | 10/2/2026 | 17/6/2026 | Due to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transaction code and modify the text data in the system. This vulnerability has a high impact on integrity of the application with no effect on the confidentiality and… | |
| Aplazada | Crítica (9.3) | 0.81% | — | Basis BBJAI | 20/11/2025 | 17/6/2026 | BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allows unauthenticated directory traversal sequences to cause the server to read arbitrary system files accessible to the account running the service. Retrieved configuration… | |
| Analizada | Media (4.3) | 0.22% | — | SAP Basis | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability | |
| Analizada | Media (4.3) | 0.22% | — | SAP Basis | 9/9/2025 | 17/6/2026 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application | |
| Analizada | Media (5.4) | 0.20% | — | SAP Basis | 12/8/2025 | 17/6/2026 | The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the… | |
| Analizada | Media (6.1) | 0.22% | — | SAP Basis | 8/7/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page generation to create content which when… | |
| Analizada | Media (4.3) | 0.23% | — | SAP Basis | 8/7/2025 | 17/6/2026 | Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability… | |
| Aplazada | Alta (7.7) | 0.41% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high… | |
| Aplazada | Alta (8.5) | 0.31% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 10/6/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data. | |
| Analizada | Alta (7.5) | 0.35% | — | SAP Basis | 11/2/2025 | 17/6/2026 | SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability. | |
| Analizada | Alta (8.8) | 0.58% | — | SAP Basis | 14/1/2025 | 17/6/2026 | Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application | |
| Analizada | Alta (8.8) | 0.74% | — | SAP Basis | 14/1/2025 | 17/6/2026 | SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability. | |
| Analizada | Media (6.5) | 0.34% | — | SAP Basis | 14/1/2025 | 17/6/2026 | In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable. | |
| Analizada | Media (5.3) | 0.34% | — | SAP Basis | 14/1/2025 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and… | |
| Analizada | Media (4.7) | 0.31% | — | SAP Basis | 9/7/2024 | 17/6/2026 | Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidentiality, integrity, and availability. | |
| Analizada | Media (5.3) | 0.30% | — | SAP Basis | 9/7/2024 | 17/6/2026 | Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the… | |
| Modificada | Media (5) | 0.35% | — | SAP Business WorkflowSAP Basis | 9/7/2024 | 17/6/2026 | WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application. | |
| Analizada | Crítica (9) | 0.40% | — | SAP Basis | 14/5/2024 | 17/6/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or… | |
| Modificada | Media (5.4) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images… | |
| Modificada | Media (4.6) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the… | |
| Modificada | Alta (8.8) | 0.89% | — | SAP Basis | 13/12/2022 | 17/6/2026 | Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful… | |
| Modificada | Media (4.3) | 0.72% | — | SAP Basis | 14/1/2020 | 17/6/2026 | Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information. | |
| Modificada | Media (5.9) | 1.6% | — | SAP NetweaverSAP Basis | 8/1/2019 | 17/6/2026 | Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted. |