SAP HANA是德国思爱普(SAP)公司的一套高性能的实时数据分析平台。该平台提供数据查询功能,支持用户对查询实时业务数据进行查询和分析。Extended Application Services是一个应用程序服务器、Web服务器和SAP HANA System内Web应用的开发环境。 SAP HANA中存在身份验证绕过漏洞。远程攻击者可利用该漏洞绕过身份验证机制并获取未授权的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP SE | SAP HANA Extended Application Services | < 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-0251 | SAP BusinessObjects Business Intelligence Platform 跨站脚本漏洞 | |
| CVE-2019-0254 | SAP Disclosure Management 跨站脚本漏洞 | |
| CVE-2019-0256 | SAP Business One Mobile App for Android 信息泄露漏洞 | |
| CVE-2019-0257 | SAP Netweaver 安全漏洞 | |
| CVE-2019-0258 | SAP Disclosure Management 安全漏洞 | |
| CVE-2019-0259 | SAP BusinessObjects Business Intelligence Platform 安全漏洞 | |
| CVE-2019-0262 | SAP Web Intelligence BI LaunchPad 跨站脚本漏洞 | |
| CVE-2019-0265 | SAP Netweaver ABAP 代码问题漏洞 | |
| CVE-2019-0266 | SAP HANA Extended Application Service 信息泄露漏洞 | |
| CVE-2019-0267 | SAP Manufacturing Integration and Intelligence 跨站请求伪造漏洞 |
No comments yet