Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.9)0.55%—SAP Business Planning AND ConsolidationAISAP Business WarehouseAI14/4/202617/6/2026
Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the system.
Pendiente de análisisMedia (5.9)0.29%—SAP Business WarehouseAI10/3/202617/6/2026
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing…
AplazadaMedia (6.1)0.24%—SAP Business WarehouseAI8/7/202517/6/2026
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
AplazadaMedia (4.3)0.22%—SAP Business WarehouseAISAP Bw/4hanaAI8/7/202517/6/2026
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of…
AplazadaBaja (2.7)0.43%—SAP Netweaver Business WarehouseAISAP CcawAI8/7/202517/6/2026
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the…
AplazadaAlta (7.7)0.41%—SAP Business WarehouseAISAP Plug-in BasisAI8/7/202517/6/2026
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high…
AplazadaAlta (8.5)0.31%—SAP Business WarehouseAISAP Plug-in BasisAI10/6/202517/6/2026
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data.
AplazadaMedia (5.7)0.21%—SAP Business WarehouseAI11/3/202517/6/2026
SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or…
AplazadaMedia (4.3)0.26%—SAP Business WarehouseAISAP BEX AnalyzerAI10/9/202417/6/2026
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
AnalizadaMedia (5.4)0.24%—SAP Business WarehouseSAP Business Warehouse Virtual Comp9/7/202417/6/2026
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the…
AnalizadaMedia (6.1)0.26%—SAP Business WarehouseSAP Business Warehouse Virtual Comp9/7/202417/6/2026
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application.
ModificadaMedia (6.5)0.44%—SAP Business WarehouseSAP Bw/4hana11/7/202317/6/2026
The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the…
ModificadaMedia (6.5)1.9%—SAP Business Warehouse12/1/202117/6/2026
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.
ModificadaAlta (8.8)3.1%—SAP Business WarehouseSAP Bw/4hana12/1/202117/6/2026
SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get…
ModificadaCrítica (9.9)3.7%—SAP Business Warehouse12/1/202117/6/2026
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully…
ModificadaCrítica (9.1)2.2%—SAP Business WarehouseSAP Bw/4hana9/12/202017/6/2026
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft…
ModificadaMedia (6.1)0.96%—SAP Business Warehouse Universal Data Integration12/12/201717/6/2026
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs.
ModificadaAlta (7.5)1.2%—SAP Netweaver Business Warehouse6/11/201417/6/2026
SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (3.5)1.9%—SAP Netweaver Business Warehouse31/7/201417/6/2026
The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Orbitaley — Vulnerabilidades