Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
SAP Enterprise Portal 代码问题漏洞
Vulnerability Description
SAP Enterprise Portal是德国思爱普(SAP)公司的一个应用软件。一个综合性的集成和应用程序平台,可促进跨组织和技术边界的人员、信息和业务流程的一致性。 SAP Enterprise Portal存在代码问题漏洞,该漏洞的存在是由于对用户提供的输入验证不足。远程攻击者可利用该漏洞可以发送一个特别制作的HTTP请求,并欺骗应用程序向任意系统发起请求。该漏洞允许远程攻击者可利用该漏洞执行SSRF攻击。
CVSS Information
N/A
Vulnerability Type
N/A