Skip to content

File tree

advisories/unreviewed/2026/03/GHSA-36m7-49vh-x3qh/GHSA-36m7-49vh-x3qh.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-36m7-49vh-x3qh",
4-
"modified": "2026-03-27T18:31:25Z",
4+
"modified": "2026-05-12T03:31:26Z",
55
"published": "2026-03-27T15:30:25Z",
66
"aliases": [
77
"CVE-2026-32859"

advisories/unreviewed/2026/03/GHSA-39xw-9qh5-7xj4/GHSA-39xw-9qh5-7xj4.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,9 @@
3737
}
3838
],
3939
"database_specific": {
40-
"cwe_ids": [],
40+
"cwe_ids": [
41+
"CWE-552"
42+
],
4143
"severity": "MODERATE",
4244
"github_reviewed": false,
4345
"github_reviewed_at": null,

advisories/unreviewed/2026/04/GHSA-gxx6-2vwg-3gc3/GHSA-gxx6-2vwg-3gc3.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-gxx6-2vwg-3gc3",
4-
"modified": "2026-04-02T21:32:52Z",
4+
"modified": "2026-05-12T03:31:26Z",
55
"published": "2026-04-01T15:31:15Z",
66
"aliases": [
77
"CVE-2026-34430"
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-296w-48hc-3xvf",
4+
"modified": "2026-05-12T03:31:27Z",
5+
"published": "2026-05-12T03:31:27Z",
6+
"aliases": [
7+
"CVE-2026-40136"
8+
],
9+
"details": "SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40136"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://me.sap.com/notes/3713521"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://url.sap/sapsecuritypatchday"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-404"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-05-12T03:16:12Z"
39+
}
40+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2hpj-h2fj-2jg5",
4+
"modified": "2026-05-12T03:31:26Z",
5+
"published": "2026-05-12T03:31:26Z",
6+
"aliases": [
7+
"CVE-2026-45393"
8+
],
9+
"details": "Reserved. Details will be published at disclosure.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45393"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://docs.cribl.io/edge/release-notes/release-v4171#security-fixes"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://trust.cribl.io/notifications"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-05-12T02:16:13Z"
32+
}
33+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-6gcc-j9m6-4752",
4+
"modified": "2026-05-12T03:31:26Z",
5+
"published": "2026-05-12T03:31:26Z",
6+
"aliases": [
7+
"CVE-2026-45392"
8+
],
9+
"details": "Reserved. Details will be published at disclosure.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45392"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://docs.cribl.io/stream/release-notes/release-v4171#security-fixes"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://trust.cribl.io/notifications"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-05-12T02:16:13Z"
32+
}
33+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-75qg-6cmg-3h9p",
4+
"modified": "2026-05-12T03:31:27Z",
5+
"published": "2026-05-12T03:31:27Z",
6+
"aliases": [
7+
"CVE-2026-40131"
8+
],
9+
"details": "SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability of the application. There is no impact on integrity.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40131"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://me.sap.com/notes/3726962"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://url.sap/sapsecuritypatchday"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-89"
34+
],
35+
"severity": "LOW",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-05-12T03:16:11Z"
39+
}
40+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-8w5g-hw8f-fqqg",
4+
"modified": "2026-05-12T03:31:27Z",
5+
"published": "2026-05-12T03:31:27Z",
6+
"aliases": [
7+
"CVE-2026-40135"
8+
],
9+
"details": "An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40135"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://me.sap.com/notes/3730019"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://url.sap/sapsecuritypatchday"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-77"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-05-12T03:16:12Z"
39+
}
40+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-c3wc-2h7r-75f9",
4+
"modified": "2026-05-12T03:31:26Z",
5+
"published": "2026-05-12T03:31:26Z",
6+
"aliases": [
7+
"CVE-2026-0502"
8+
],
9+
"details": "Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0502"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://me.sap.com/notes/3667593"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://url.sap/sapsecuritypatchday"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-352"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-05-12T03:16:10Z"
39+
}
40+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-cqhw-vpw6-ww5x",
4+
"modified": "2026-05-12T03:31:26Z",
5+
"published": "2026-05-12T03:31:26Z",
6+
"aliases": [
7+
"CVE-2026-34259"
8+
],
9+
"details": "Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or shut down the system, resulting in a complete compromise of confidentiality, integrity, and availability.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34259"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://me.sap.com/notes/3732471"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://url.sap/sapsecuritypatchday"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-77"
34+
],
35+
"severity": "HIGH",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-05-12T03:16:11Z"
39+
}
40+
}

0 commit comments

Comments
 (0)