Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | SAP Business Planning AND ConsolidationAISAP Business WarehouseAI | 14/4/2026 | 17/6/2026 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system. | |
| Pendiente de análisis | Media (5.9) | 0.29% | — | SAP Business WarehouseAI | 10/3/2026 | 17/6/2026 | Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing… | |
| Aplazada | Media (6.1) | 0.24% | — | SAP Business WarehouseAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Business WarehouseAISAP Bw/4hanaAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of… | |
| Aplazada | Baja (2.7) | 0.43% | — | SAP Netweaver Business WarehouseAISAP CcawAI | 8/7/2025 | 17/6/2026 | SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the… | |
| Aplazada | Alta (7.7) | 0.41% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 8/7/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high… | |
| Aplazada | Alta (8.5) | 0.31% | — | SAP Business WarehouseAISAP Plug-in BasisAI | 10/6/2025 | 17/6/2026 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data. | |
| Aplazada | Media (5.7) | 0.21% | — | SAP Business WarehouseAI | 11/3/2025 | 17/6/2026 | SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or… | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Business WarehouseAISAP BEX AnalyzerAI | 10/9/2024 | 17/6/2026 | Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. | |
| Analizada | Media (5.4) | 0.24% | — | SAP Business WarehouseSAP Business Warehouse Virtual Comp | 9/7/2024 | 17/6/2026 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the… | |
| Analizada | Media (6.1) | 0.26% | — | SAP Business WarehouseSAP Business Warehouse Virtual Comp | 9/7/2024 | 17/6/2026 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application. | |
| Modificada | Media (6.5) | 0.44% | — | SAP Business WarehouseSAP Bw/4hana | 11/7/2023 | 17/6/2026 | The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the… | |
| Modificada | Media (6.5) | 1.9% | — | SAP Business Warehouse | 12/1/2021 | 17/6/2026 | The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table. | |
| Modificada | Alta (8.8) | 3.1% | — | SAP Business WarehouseSAP Bw/4hana | 12/1/2021 | 17/6/2026 | SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get… | |
| Modificada | Crítica (9.9) | 3.7% | — | SAP Business Warehouse | 12/1/2021 | 17/6/2026 | The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully… | |
| Modificada | Crítica (9.1) | 2.2% | — | SAP Business WarehouseSAP Bw/4hana | 9/12/2020 | 17/6/2026 | SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft… | |
| Modificada | Media (6.1) | 0.96% | — | SAP Business Warehouse Universal Data Integration | 12/12/2017 | 17/6/2026 | Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs. | |
| Modificada | Alta (7.5) | 1.2% | — | SAP Netweaver Business Warehouse | 6/11/2014 | 17/6/2026 | SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.9% | — | SAP Netweaver Business Warehouse | 31/7/2014 | 17/6/2026 | The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors. |