Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.25% | — | SAP Manufacturing Integration AND IntelligenceAI | 8/9/2026 | 8/9/2026 | Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users… | |
| Pendiente de análisis | Alta (7.3) | 0.38% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete… | |
| Pendiente de análisis | Alta (7.3) | 0.32% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation… | |
| Pendiente de análisis | Alta (7.6) | 0.40% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the… | |
| Pendiente de análisis | Crítica (9.1) | 0.77% | — | SAP Manufacturing Integration AND IntelligenceAI | 11/8/2026 | 26/8/2026 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating… | |
| Modificada | Alta (8.8) | 52% | — | SAP Manufacturing Integration AND Intelligence | 9/3/2021 | 17/6/2026 | SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role,… | |
| Modificada | Alta (8.8) | 0.72% | — | SAP Manufacturing Integration AND Intelligence | 15/2/2019 | 17/6/2026 | SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application. | |
| Modificada | Media (5) | 0.97% | — | SAP Manufacturing Integration AND Intelligence | 24/11/2015 | 17/6/2026 | SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274. |