Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-10040

Publication date:
14/07/2020
A vulnerability has been identified in SICAM MMU (All versions
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2020

CVE-2020-10039

Publication date:
14/07/2020
A vulnerability has been identified in SICAM MMU (All versions
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2020

CVE-2020-6290

Publication date:
14/07/2020
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-6291

Publication date:
14/07/2020
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-6292

Publication date:
14/07/2020
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-6289

Publication date:
14/07/2020
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.
Severity CVSS v4.0: Pending analysis
Last modification:
15/07/2020

CVE-2020-6287

Publication date:
14/07/2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Severity CVSS v4.0: Pending analysis
Last modification:
31/10/2025

CVE-2020-6276

Publication date:
14/07/2020
SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-6281

Publication date:
14/07/2020
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-6278

Publication date:
14/07/2020
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-4513

Publication date:
14/07/2020
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182368.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020

CVE-2020-4512

Publication date:
14/07/2020
IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.
Severity CVSS v4.0: Pending analysis
Last modification:
14/07/2020