Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.29% | — | SAP Netweaver Application Server JavaAIAdobe Document ServiceAI | 11/8/2026 | 26/8/2026 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though… | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | SAP Netweaver Application Server JavaAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the… | |
| Pendiente de análisis | Crítica (9) | 0.63% | — | SAP Netweaver Application Server JavaAI | 9/6/2026 | 23/7/2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive… | |
| Analizada | Media (6.1) | 0.29% | — | SAP Netweaver Application Server Java | 14/4/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that… | |
| Analizada | Baja (3.4) | 0.17% | — | SAP Netweaver Application Server Java | 10/2/2026 | 17/6/2026 | Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing… | |
| Aplazada | Baja (3) | 0.14% | — | SAP Netweaver Application Server JavaAI | 13/1/2026 | 17/6/2026 | The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial… | |
| Aplazada | Media (5.3) | 0.46% | — | SAP Netweaver Application Server JavaAI | 11/11/2025 | 17/6/2026 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access to sensitive… | |
| Analizada | Media (5.3) | 0.30% | — | SAP Netweaver Application Server Java | 9/9/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gather additional sensitive information about the system.This… | |
| Aplazada | Baja (3.5) | 0.14% | — | SAP Netweaver Application Server JavaAI | 8/7/2025 | 17/6/2026 | The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound connection being… | |
| Aplazada | Media (5.4) | 0.22% | — | SAP Netweaver Application Server JavaAI | 11/3/2025 | 17/6/2026 | User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data… | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely… | |
| Aplazada | Media (5.4) | 0.27% | — | SAP Netweaver Application Server JavaAI | 11/2/2025 | 17/6/2026 | SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the… | |
| Aplazada | Media (6.3) | 0.26% | — | SAP Netweaver Application Server JavaAI | 14/1/2025 | 17/6/2026 | Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and… | |
| Modificada | Alta (7.5) | 0.54% | — | SAP Netweaver Application Server Java | 11/6/2024 | 17/6/2026 | Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application. | |
| Modificada | Media (5.3) | 0.33% | — | SAP Netweaver Application Server Java | 11/6/2024 | 17/6/2026 | SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application. | |
| Analizada | Crítica (9.1) | 1.6% | — | SAP Netweaver Application Server Java | 12/3/2024 | 17/6/2026 | SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity… | |
| Modificada | Alta (7.5) | 0.52% | — | SAP Netweaver Application Server Java | 13/2/2024 | 17/6/2026 | SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability… | |
| Modificada | Alta (8.8) | 0.52% | — | SAP Netweaver Application Server Java | 13/2/2024 | 17/6/2026 | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on… | |
| Modificada | Media (5.3) | 0.55% | — | SAP Netweaver Application Server Java | 14/11/2023 | 17/6/2026 | The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability. | |
| Modificada | Media (6.5) | 0.41% | — | SAP Netweaver Application Server Java | 10/10/2023 | 17/6/2026 | SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application. | |
| Modificada | Crítica (9.8) | 0.88% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a… | |
| Modificada | Alta (7.5) | 0.75% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information. | |
| Modificada | Media (5.3) | 0.58% | — | SAP Netweaver Application Server Java | 14/3/2023 | 17/6/2026 | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive… | |
| Modificada | Media (6.1) | 0.45% | — | SAP Netweaver Application Server Java | 12/12/2022 | 17/6/2026 | Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of… | |
| Modificada | Media (5.3) | 0.77% | — | SAP Netweaver Application Server Java | 10/3/2022 | 17/6/2026 | Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks. |