SAP Business One是德国思爱普(SAP)公司的一套适用于小型企业的业务管理软件。该软件包括财务管理、客户关系管理和人力资源管理等功能。Service Layer是其中的一个能够通过Web服务调用SAP Business One的对象和服务的程序接口。 SAP Business One 9.2版本和9.3版本中的Service Layer存在跨站脚本漏洞。远程攻击者可利用该漏洞在用户浏览器中执行任意脚本代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | SAP Business One Service Layer (B1_ON_HANA) | = 9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-2486 | SAP Marketing 跨站脚本漏洞 | |
| CVE-2018-2492 | SAP NetWeaver AS Java 安全漏洞 | |
| CVE-2018-2494 | SAP NetWeaver SAP Basis AS ABAP 安全漏洞 | |
| CVE-2018-2497 | SAP HANA 输入验证错误漏洞 | |
| CVE-2018-2500 | SAP Mobile Secure Android Client 信息泄露漏洞 | |
| CVE-2018-2503 | SAP NetWeaver AS Java 安全漏洞 | |
| CVE-2018-2504 | SAP NetWeaver AS Java Web Container service 跨站脚本漏洞 | |
| CVE-2018-2505 | SAP Commerce 跨站脚本漏洞 |
No comments yet