Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.34%—SAP S/4hanaAI8/9/20268/9/2026
SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no…
Pendiente de análisisBaja (3.5)0.14%—SAP S/4hana FinanceAI8/9/20269/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web…
Pendiente de análisisBaja (3.5)0.14%—SAP S/4hana FinanceAI8/9/20268/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web…
Pendiente de análisisMedia (4.6)0.13%—SAP S/4hana FinanceAI8/9/20268/9/2026
SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server…
Pendiente de análisisMedia (6.5)0.39%—SAP S/4hanaAI8/9/20268/9/2026
SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality,…
Pendiente de análisisAlta (7.5)0.51%—SAP S/4hanaAI25/8/202626/8/2026
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system…
Pendiente de análisisMedia (4.3)0.28%—SAP S/4hanaAI11/8/202626/8/2026
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and…
Pendiente de análisisMedia (4.3)0.28%—SAP S/4hanaAI14/7/202614/7/2026
SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisMedia (5.5)0.31%—SAP S/4hanaAI14/7/202614/7/2026
SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.
Pendiente de análisisBaja (3.7)0.35%—SAP Hana DatabaseAI14/7/202614/7/2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low…
Pendiente de análisisMedia (6.5)0.38%—SAP S/4hanaAI9/6/202623/7/2026
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database queries.This flaw exposes sensitive information to which they should not otherwise have access to. The…
Pendiente de análisisMedia (6.3)0.27%—SAP S/4hanaAI12/5/202617/6/2026
Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the legitimate user from…
Pendiente de análisisCrítica (9.6)0.43%—SAP S/4hanaAI12/5/202617/6/2026
SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the underlying database…
AnalizadaMedia (4.3)0.35%—SAP Hana CockpitSAP Hana Database Explorer14/4/202617/6/2026
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
Pendiente de análisisAlta (7.1)0.34%—SAP ERPAISAP S/4hanaAI14/4/202617/6/2026
Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacker could execute a particular ABAP report to overwrite any existing eight?character executable ABAP report without authorization. If the overwritten report is subsequently executed, the intended…
Pendiente de análisisMedia (6.5)0.31%—SAP S/4hanaAI14/4/202617/6/2026
Due to missing authorization checks in the SAP S/4HANA backend OData Service (Manage Reference Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not…
Pendiente de análisisMedia (6.5)0.31%—SAP S/4hanaAI14/4/202617/6/2026
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Reference Equipment), an attacker could update and delete child entities via OData services without proper authorization. This vulnerability has a high impact on integrity, while confidentiality and availability are not impacted.
Pendiente de análisisMedia (4.3)0.26%—SAP S/4hanaAI14/4/202617/6/2026
Due to missing authorization checks in the SAP S/4HANA OData Service (Manage Technical Object Structures), an attacker could update and delete child entities via exposed OData services without proper authorization. This vulnerability results in a low impact on integrity, while confidentiality and availability are not…
Pendiente de análisisMedia (4.9)0.25%—SAP S/4hanaAI14/4/202617/6/2026
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
Pendiente de análisisMedia (5.8)0.33%—SAP S/4hana HCM PortugalAISAP ERP HCM PortugalAI10/3/202617/6/2026
Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.
AnalizadaMedia (4.3)0.20%—SAP S/4hana Uiapfi70SAP S/4hana Uis4h24/2/202617/6/2026
Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.
AnalizadaMedia (4.3)0.21%—SAP S/4hana Defense & Security10/2/202617/6/2026
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or…
AnalizadaCrítica (9.9)0.52%—SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework10/2/202617/6/2026
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on…
AplazadaMedia (6.4)0.23%—SAP ERP Central ComponentAISAP EHS ManagementAISAP S/4hanaAI13/1/202617/6/2026
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or…
AplazadaCrítica (9.9)0.47%—SAP S/4hanaAI13/1/202617/6/2026
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.