Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP GRC 安全漏洞
Vulnerability Description
SAP GRC是德国思爱普(SAP)公司的一套解决方案和产品。可帮助您以最小化风险、建立信任并降低合规成本的方式管理企业资源。 SAP GRC存在安全漏洞,该漏洞源于远程启用功能模块使经过身份验证的攻击者能够以最小权限访问数据库中存储的所有机密数据。攻击者利用该漏洞可以从特定于客户端的数据库表中获取用户凭据,从而对机密性造成重大影响。
CVSS Information
N/A
Vulnerability Type
N/A