Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.37% | — | SAP Financial ConsolidationAI | 12/5/2026 | 17/6/2026 | SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data | |
| Aplazada | Crítica (9.8) | 0.60% | — | SAP Financial ConsolidationAI | 8/4/2025 | 17/6/2026 | SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application. | |
| Aplazada | Media (5) | 0.30% | — | SAP Financial ConsolidationAI | 11/6/2024 | 17/6/2026 | SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact… | |
| Aplazada | Alta (8.1) | 0.37% | — | SAP Financial ConsolidationAI | 11/6/2024 | 17/6/2026 | SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are exposed over the network and it allows the user to modify the content from the web site. On successful exploitation, an attacker can cause significant impact to confidentiality and integrity of the… | |
| Modificada | Media (6.1) | 0.44% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the… | |
| Modificada | Media (6.5) | 0.40% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on… | |
| Modificada | Media (5.4) | 0.44% | — | SAP Financial Consolidation | 8/11/2022 | 17/6/2026 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application. | |
| Modificada | Media (5.3) | 0.70% | — | SAP Financial Consolidation | 10/3/2022 | 17/6/2026 | SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message. | |
| Modificada | Media (6.5) | 0.72% | — | SAP Financial Consolidation | 8/10/2019 | 17/6/2026 | Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection. | |
| Modificada | Media (5.4) | 0.53% | — | SAP Financial Consolidation | 8/10/2019 | 17/6/2026 | SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to reflected cross site scripting vulnerability. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Financial Consolidation Cube DesignerSAP Financial Consolidation Cube Designer Bobj Eades | 8/1/2019 | 17/6/2026 | A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user. | |
| Modificada | Media (6.1) | 1.3% | — | SAP Businessobjects Financial Consolidation | 14/8/2018 | 17/6/2026 | SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.64% | — | SAP Businessobjects Financial Consolidation | 3/12/2017 | 17/6/2026 | Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292. | |
| Modificada | Media (4.7) | 1.6% | — | SAP Businessobjects Financial Consolidation | 16/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106. | |
| Modificada | Media (5) | 1.8% | — | Oracle Financial Consolidation HUB | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Financial Consolidation Hub component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Business Intelligence. |