Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SAP R/3 Web Application Server Demo saposcol权限许可和访问控制漏洞
Vulnerability Description
SAP R/3 Web Application Server Demo 1.5之前版本的saposcol信任PATH环境变量查找并执行expand程序。本地用户可以通过修改指向Trojanhorse expand程序的PATH获得根目录访问权限。
CVSS Information
N/A
Vulnerability Type
N/A