Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.32%—Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI1/9/20261/9/2026
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion…
Pendiente de análisisAlta (8.8)0.49%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI7/7/20268/7/2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds…
Pendiente de análisisAlta (7.6)0.68%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI11/6/202615/7/2026
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of…
AnalizadaAlta (8.8)0.78%—Microsoft Azure Privileged Identity Management22/5/202623/7/2026
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisMedia (6.9)0.24%—Pingidentity PingidmAIForgerock Identity ManagementAI7/4/202624/7/2026
An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept…
AplazadaBaja (3.8)0.19%—SAP Identity ManagementAI13/1/202617/6/2026
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to submit specially crafted malicious REST requests that are processed by JNDI operations without adequate input neutralization. This may lead to limited disclosure or modification of data, resulting in…
ModificadaAlta (7.8)0.29%—Juniper Identity Management Service14/4/202217/6/2026
An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (JIMS) allows an unprivileged user to trigger a repair operation. Running a repair operation, in turn, will trigger a number of file operations in the %TEMP% folder of the…
ModificadaAlta (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+2218/1/202217/6/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
ModificadaCrítica (9.8)67%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2418/1/202217/6/2026
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or…
ModificadaAlta (8.8)64%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2218/1/202217/6/2026
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink…
ModificadaMedia (5.9)100%—Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+11218/12/202125/8/2026
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j…
ModificadaAlta (7.5)81%—Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaMedia (6.5)0.68%—SAP Identity Management12/5/202017/6/2026
SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.
ModificadaAlta (8.8)1.1%—SAP Identity Management14/5/201917/6/2026
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing.
ModificadaMedia (4.2)0.29%—Juniper Identity Management Service10/4/201917/6/2026
Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain connected Windows system to bypass SRX firewall policies, or trigger a Denial of Service (DoS)…
ModificadaAlta (7.3)0.45%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance11/7/201817/6/2026
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted…
ModificadaMedia (5.3)1.3%—SAP Identity Management9/5/201817/6/2026
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.
ModificadaMedia (5.4)1.5%—SAP Identity Management9/5/201817/6/2026
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
ModificadaAlta (7.8)0.41%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance8/3/201817/6/2026
An issue was discovered in EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels (hardware appliance and software bundle deployments only); RSA Via Lifecycle and Governance version 7.0, all patch levels (hardware appliance and software bundle deployments only); RSA Identity Management &…
ModificadaMedia (5.4)1.2%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance17/7/201717/6/2026
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all…
ModificadaAlta (7.2)2.1%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance17/7/201717/6/2026
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch…
ModificadaMedia (5.4)0.97%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance9/6/201717/6/2026
EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site Scripting vulnerabilities that could potentially be exploited by…
ModificadaMedia (6.1)1.2%—EMC RSA Identity Governance AND LifecycleEMC RSA Identity Management AND GovernanceRSA VIA Lifecycle AND Governance9/6/201717/6/2026
EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Reflected Cross Site Scripting vulnerabilities that could potentially be exploited…
ModificadaCrítica (9.8)90%—Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaMedia (4.3)1.1%—EMC RSA Identity Management AND GovernanceEMC RSA VIA Lifecycle AND Governance24/9/201617/6/2026
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.