Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.30% | — | SAP Landscape Management | 9/7/2024 | 17/6/2026 | SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities. | |
| Analizada | Crítica (9.8) | 0.59% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Enterprise Storage Integrator FOR SAP Landscape Management | 15/2/2024 | 17/6/2026 | DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials. | |
| Modificada | Alta (8.7) | 0.56% | — | SAP Landscape Management | 11/4/2023 | 17/6/2026 | An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information… | |
| Modificada | Alta (7.2) | 1.2% | — | SAP Adaptive ExtensionsSAP Landscape Management | 14/4/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context,… | |
| Modificada | Alta (7.2) | 1.7% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | |
| Modificada | Alta (7.2) | 1.6% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. | |
| Modificada | Media (4.9) | 0.88% | — | SAP Landscape Management | 8/10/2019 | 17/6/2026 | Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. | |
| Modificada | Crítica (9.8) | 3.6% | — | SAP Landscape Management | 15/2/2019 | 17/6/2026 | Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)). | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Landscape Management | 8/1/2019 | 17/6/2026 | Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. |