Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an…
ModificadaMedia (5.9)0.86%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory…
ModificadaAlta (8.8)0.70%—SAP Businessobjects Business IntelligenceSAP Internet Graphics Server14/8/201817/6/2026
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
ModificadaMedia (5.9)1.5%—SAP Internet Graphics Server10/7/201817/6/2026
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require…
ModificadaAlta (7.5)1.9%—SAP Internet Graphics Server10/7/201817/6/2026
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModificadaCrítica (9.1)3.3%—SAP Internet Graphics Server10/7/201817/6/2026
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
ModificadaAlta (7.5)2.4%—SAP Internet Graphics Server9/5/201817/6/2026
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModificadaAlta (7.5)1.9%—SAP Internet Graphics Server9/5/201817/6/2026
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModificadaAlta (7.5)2.4%—SAP Internet Graphics Server9/5/201817/6/2026
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
ModificadaCrítica (9.8)1.5%—SAP Internet Graphics Server9/5/201817/6/2026
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
ModificadaMedia (6.5)0.91%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
ModificadaAlta (8.8)1.5%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
ModificadaMedia (6.5)1.0%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
ModificadaAlta (7.5)15%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
ModificadaAlta (7.5)41%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
ModificadaMedia (6.5)0.91%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS portwatcher service.
ModificadaMedia (6.5)0.91%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.
ModificadaMedia (5.7)0.70%—SAP Internet Graphics Server14/2/201817/6/2026
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
ModificadaMedia (6.1)0.64%—SAP Internet Graphics Server14/2/201817/6/2026
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
ModificadaMedia (6.5)0.85%—SAP Internet Graphics Server14/2/201817/6/2026
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, which is not available to the user otherwise.