SAP ERP HCM是德国思爱普(SAP)公司的一套企业人力资源管理解决方案。SAP Fiori是其中的一个产品前端开发框架。 SAP ERP HCM的SAP Fiori 1.0版本中存在跨站请求伪造漏洞,该漏洞源于应用程序未能妥当地验证HTTP请求。远程攻击者可利用该漏洞执行未授权的操作和访问受影响的程序。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-2466 | SAP Data Services 跨站脚本漏洞 | |
| CVE-2018-2467 | SAP BusinessObjects Business Intelligence Platform Servers Software Development Kit 信息泄露漏洞 | |
| CVE-2018-2468 | SAP Adaptive Server Enterprise 信息泄露漏洞 | |
| CVE-2018-2469 | SAP Adaptive Server Enterprise 信息泄露漏洞 | |
| CVE-2018-2470 | SAP NetWeaver Application Server for ABAP 跨站脚本漏洞 | |
| CVE-2018-2471 | SAP BusinessObjects Business Intelligence Platform 信息泄露漏洞 | |
| CVE-2018-2472 | SAP BusinessObjects Business Intelligence Platform 跨站脚本漏洞 | |
| CVE-2018-2475 | Gardener 访问控制错误漏洞 |
No comments yet