Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2) | 0.24% | — | SAP Landscape TransformationAI | 14/4/2026 | 17/6/2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a… | |
| Aplazada | Crítica (9.1) | 0.51% | — | SAP Landscape TransformationAI | 13/1/2026 | 17/6/2026 | SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Crítica (9.9) | 0.70% | — | SAP Landscape TransformationAI | 12/8/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Alta (7.7) | 0.35% | — | SAP Landscape TransformationAI | 13/5/2025 | 17/6/2026 | Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application. | |
| Aplazada | Crítica (9.9) | 0.74% | — | SAP Landscape TransformationAI | 8/4/2025 | 17/6/2026 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Modificada | Media (5.7) | 0.30% | — | SAP Landscape Management | 9/7/2024 | 17/6/2026 | SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities. | |
| Analizada | Crítica (9.8) | 0.59% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Modificada | Alta (8.8) | 0.26% | — | Arulprasadj Prevent Landscape Rotation | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0. | |
| Modificada | Media (6.1) | 0.32% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape allowed URLs which caused open redirection. | |
| Modificada | Alta (8.2) | 0.45% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. | |
| Modificada | Alta (7.5) | 0.55% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. | |
| Modificada | Alta (8.7) | 0.56% | — | SAP Landscape Management | 11/4/2023 | 17/6/2026 | An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information… | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Landscape TransformationSAP Landscape Transformation Replication ServerSAP S/4hanaSAP Test Data Migration Server | 14/9/2021 | 17/6/2026 | Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise… | |
| Modificada | Alta (7.2) | 1.2% | — | SAP Adaptive ExtensionsSAP Landscape Management | 14/4/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context,… | |
| Modificada | Alta (7.2) | 1.7% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | |
| Modificada | Alta (7.2) | 1.6% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. | |
| Modificada | Media (4.9) | 0.88% | — | SAP Landscape Management | 8/10/2019 | 17/6/2026 | Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. | |
| Modificada | Crítica (9.8) | 3.6% | — | SAP Landscape Management | 15/2/2019 | 17/6/2026 | Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)). | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Landscape Management | 8/1/2019 | 17/6/2026 | Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Crítica (9.8) | 2.5% | — | SAP Netweaver System Landscape Directory | 1/3/2018 | 17/6/2026 | SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity. | |
| Modificada | Media (4.3) | 1.3% | — | SAP System Landscape DirectorySAP Netweaver | 28/7/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp. |