Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no… | |
| Analizada | Media (4.3) | 0.17% | — | SAP S4core | 10/2/2026 | 17/6/2026 | SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted. | |
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the… | |
| Aplazada | Media (4.3) | 0.24% | — | SAP S4coreAI | 11/11/2025 | 17/6/2026 | SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on confidentiality of the application with no impact on integrity and availability of the application. | |
| Aplazada | Media (4.3) | 0.30% | — | SAP S4coreAI | 13/5/2025 | 17/6/2026 | SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted. | |
| Aplazada | Media (4.3) | 0.29% | — | SAP S4coreAI | 8/4/2025 | 17/6/2026 | SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted. | |
| Modificada | Media (5.4) | 0.30% | — | SAP S4core | 9/7/2024 | 17/6/2026 | SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity. | |
| Modificada | Media (6.5) | 0.42% | — | SAP S4coreSAP S4coreop | 9/7/2024 | 17/6/2026 | Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application. | |
| Modificada | Media (5.4) | 0.37% | — | SAP S4core | 12/9/2023 | 17/6/2026 | S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no… | |
| Modificada | Alta (7.3) | 0.38% | — | SAP S4core | 11/7/2023 | 17/6/2026 | When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted,… | |
| Modificada | Media (5.5) | 0.15% | — | SAP S4coreSAP Vendor Master Hierarchy | 9/5/2023 | 17/6/2026 | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to… | |
| Modificada | Media (5.4) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images… | |
| Modificada | Media (4.6) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the… | |
| Modificada | Crítica (9.1) | 2.1% | — | SAP DmisSAP S4coreSapscore | 15/9/2021 | 17/6/2026 | DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to… | |
| Modificada | Alta (8.1) | 0.68% | — | SAP ERP (ea-finserv)SAP ERP (s4core) | 10/6/2020 | 17/6/2026 | Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to… | |
| Modificada | Alta (8.8) | 0.98% | — | SAP Master Data Governance (s4core)SAP Master Data Governance (s4fnd)Master Data Governance (sap BS Fnd) | 12/5/2020 | 17/6/2026 | The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection. | |
| Modificada | Media (4.3) | 0.63% | — | SAP Treasury AND Risk Management (ea-finserv)SAP Treasury AND Risk Management (s4core) | 10/3/2020 | 17/6/2026 | The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check. | |
| Modificada | Alta (8.8) | 0.89% | — | SAP Enterprise Extension Financial ServicesSAP Treasury AND Risk Management (s4core) | 17/12/2019 | 17/6/2026 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user identity. | |
| Modificada | Alta (8.8) | 1.1% | — | SAP Enterprise Extension Financial ServicesSAP Treasury AND Risk Management (s4core) | 17/12/2019 | 17/6/2026 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Alta (8.8) | 1.4% | — | SapscoreSAP S4coreSAP Ea-finservSAP Bank/cfm | 8/1/2019 | 17/6/2026 | SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |
| Modificada | Media (4.6) | 0.83% | — | SapscoreSAP S4coreSAP Ea-finserv | 9/5/2018 | 17/6/2026 | SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |