SAP BPC MS是德国思爱普(SAP)公司的一个业务规划与整合应用程序。提供规划、预算、预测和财务合并功能。 SAP BPC MS 10.0 810版本存在SQL注入漏洞,该漏洞源于其允许未经授权的攻击者执行精心制作的数据库查询实现SQL注入并允许攻击者访问、修改和/或删除后端数据库中的数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | SAP BPC MS 10.0 | 800 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-0018 | 10.0 CRITICAL | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2023-0022 | 9.9 CRITICAL | Code Injection vulnerability in SAP BusinessObjects Business Intelligence platform (Analys |
| CVE-2023-0017 | 9.4 CRITICAL | Improper access control in SAP NetWeaver AS for Java |
| CVE-2023-0014 | 9.0 CRITICAL | Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-0012 | 6.4 MEDIUM | Local Privilege Escalation in SAP Host Agent (Windows) |
| CVE-2023-0013 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-0015 | 4.6 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence (Web |
| CVE-2023-0023 | 4.5 MEDIUM | Information Disclosure in SAP Bank Account Management (Manage Banks) |
No comments yet