Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, and obtain sensitive information (cookies and SAPPASSPORT) via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SAP NetWeaver 输入验证漏洞
Vulnerability Description
SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台可为SAP应用提供开发和运行环境。 SAP NetWeaver 6.40和7.02及之前的版本中的J2EE引擎中存在安全漏洞。远程攻击者可利用该漏洞重定向用户到任意网站,实施钓鱼攻击,并获取敏感信息(cookies和SAPPASSPORT)。
CVSS Information
N/A
Vulnerability Type
N/A