SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台,该平台可为SAP应用提供开发和运行环境。SAP NetWeaver Application Server(AS) for ABAP是一款运行于NetWeaver中且基于ABAP(高级商务编程语言)的应用服务器。 SAP NetWeaver AS for ABAP中存在跨站脚本漏洞,该漏洞源于程序没有充分的编码用户控制的输入。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。以下版本受到影响:SAP NetWeaver
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | SAP NetWeaver Application Server for ABAP | from 7.0 to 7.02 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-2466 | SAP Data Services 跨站脚本漏洞 | |
| CVE-2018-2467 | SAP BusinessObjects Business Intelligence Platform Servers Software Development Kit 信息泄露漏洞 | |
| CVE-2018-2468 | SAP Adaptive Server Enterprise 信息泄露漏洞 | |
| CVE-2018-2469 | SAP Adaptive Server Enterprise 信息泄露漏洞 | |
| CVE-2018-2471 | SAP BusinessObjects Business Intelligence Platform 信息泄露漏洞 | |
| CVE-2018-2472 | SAP BusinessObjects Business Intelligence Platform 跨站脚本漏洞 | |
| CVE-2018-2474 | SAP ERP HCM SAP Fiori 跨站请求伪造漏洞 | |
| CVE-2018-2475 | Gardener 访问控制错误漏洞 |
No comments yet