漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
SAP NetWeaver 路径遍历漏洞
Vulnerability Description
SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver 7.30, 7.31, 7.40, 7.50版本存在路径遍历漏洞,被认证为非管理员用户的攻击者可以通过网络上传恶意文件并触发其处理,该文件能够运行操作系统具有 Java Server 进程特权的命令。这些命令可用于读取或修改服务器上的任何信息或关闭服务器使其不可用。
CVSS Information
N/A
Vulnerability Type
N/A