漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Privilege escalation vulnerability in SAP SuccessFactors attachment API for Mobile Application(Android & iOS)
Vulnerability Description
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and Benefits. On successful exploitation, the attacker can read/write attachments. Thus, compromising the confidentiality and integrity of the application
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
SAP SuccessFactors 安全漏洞
Vulnerability Description
SAP SuccessFactors是德国思爱普(SAP)公司的一个基于云的 Hcm 软件应用程序。 SAP SuccessFactors存在安全漏洞,该漏洞源于应用程序端点配置错误。攻击者利用该漏洞提升权限,读取或写入附件,损害了应用程序的机密性和完整性。
CVSS Information
N/A
Vulnerability Type
N/A