SAP Business One License service API是德国思爱普(SAP)公司的一项服务。提供了一个统一的服务端点,可以通过 API 调用从 SAP Business One 系统之外的源系统访问业务数据。 SAP Business one License service API 10.0版本存在访问控制错误漏洞。攻击者利用该漏洞通过网络发送恶意 http 请求,从而破坏整个应用程序。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP SE | SAP Business One License service API | 10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-35168 | SAP Business One 代码问题漏洞 | |
| CVE-2022-32246 | SAP Business Objects SQL注入漏洞 | |
| CVE-2022-31598 | SAP Business Objects 数据伪造问题漏洞 | |
| CVE-2022-31592 | SAP Enterprise Extension Defense Forces & Public Security 安全漏洞 | |
| CVE-2022-29619 | SAP BusinessObjects Business Intelligence Platform 安全漏洞 | |
| CVE-2022-31597 | SAP S/4HANA 安全漏洞 | |
| CVE-2022-31591 | SAP BusinessObjects BW Publisher Service 代码问题漏洞 | |
| CVE-2022-31593 | SAP Business One client 注入漏洞 | |
| CVE-2022-32248 | SAP S/4HANA 输入验证错误漏洞 | |
| CVE-2022-32247 | SAP NetWeaver和SAP NetWeaver Enterprise Portal 跨站脚本漏洞 | |
| CVE-2022-32249 | SAP S/4HANA 和 SAP Business One 安全漏洞 | |
| CVE-2022-35170 | SAP NetWeaver Enterprise Portal 跨站脚本漏洞 | |
| CVE-2022-35169 | SAP BusinessObjects Business Intelligence Platform 信息泄露漏洞 | |
| CVE-2022-35171 | SAP 3D Visual Enterprise Viewer 输入验证错误漏洞 | |
| CVE-2022-35172 | SAP NetWeaver和SAP NetWeaver Enterprise Portal 跨站脚本漏洞 | |
| CVE-2022-35227 | SAP NetWeaver Portal 跨站脚本漏洞 | |
| CVE-2022-35225 | SAP NetWeaver和SAP NetWeaver Enterprise Portal 跨站脚本漏洞 | |
| CVE-2022-35228 | SAP BusinessObjects Central Management Console 跨站请求伪造漏洞 | |
| CVE-2022-35224 | SAP Enterprise Portal 跨站脚本漏洞 |
No comments yet