SAP NetWeaver Process Integration(PI)是德国思爱普(SAP)公司的一套SAP企业应用程序集成软件,是NetWeaver产品组的一个组件。该组件主要用于内部系统与外部的信息交换。 SAP NetWeaver Process Integration 7.50版本存在安全漏洞,该漏洞源于未经身份验证的用户可以连接其用户定义搜索中通过JNDI公开的开放接口并使用开放的命名和目录API来访问可能执行未授权操作的服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | NetWeaver Process Integration | 7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Improper access control in SAP NetWeaver Process Integration | https://github.com/redrays-io/CVE-2022-41272 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-41267 | 9.9 CRITICAL | SAP Business Objects 代码问题漏洞 |
| CVE-2022-41271 | 9.4 CRITICAL | SAP NetWeaver Process Integration 安全漏洞 |
| CVE-2022-41264 | 8.8 HIGH | SAP Basis 代码注入漏洞 |
| CVE-2022-41268 | 8.5 HIGH | 多款产品安全漏洞 |
| CVE-2022-41266 | 8.0 HIGH | SAP Commerce跨站脚本漏洞 |
| CVE-2022-41274 | 6.5 MEDIUM | SAP Disclosure Management 信息泄露漏洞 |
| CVE-2022-41275 | 6.1 MEDIUM | SAP Solution Manager 输入验证错误漏洞 |
| CVE-2022-41273 | 4.3 MEDIUM | SAP Sourcing和SAP Contract Lifecycle Management 1100 输入验证错误漏洞 |
No comments yet