SAP Netweaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver 700, 701, 702, 730版本存在跨站脚本漏洞,该漏洞源于未充分编码用户控制的输入。攻击者可通过该漏洞使潜在受害者向易受攻击的web应用程序提供恶意内容,然后将恶意内容反映给受害者并由web浏览器执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP SE | SAP NetWeaver | < 700 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-38179 | SAP Business One 安全漏洞 | |
| CVE-2021-38181 | SAP NetWeaver AS 资源管理错误漏洞 | |
| CVE-2021-40495 | SAP NetWeaver Application Server 代码问题漏洞 | |
| CVE-2021-40497 | SAP Business Objects Analysis 安全漏洞 | |
| CVE-2021-38178 | SAP NetWeaver AS 安全漏洞 | |
| CVE-2021-38180 | SAP Business One 安全漏洞 | |
| CVE-2021-40496 | Sap Internet Communication Framework 访问控制错误漏洞 | |
| CVE-2021-40499 | SAP NetWeaver Application Server 代码注入漏洞 | |
| CVE-2021-40498 | Sap SuccessFactors 安全漏洞 | |
| CVE-2021-40500 | SAP BusinessObjects Business Intelligence Platform和SAP BusinessObjects Business Intelligen |
No comments yet