SAP NetWeaver AS是德国思爱普(SAP)公司的一款SAP网络应用服务器。它不仅能提供网络服务,且还是SAP软件的基本平台。 SAP NetWeaver AS for ABAP and ABAP Platform存在路径遍历漏洞,该漏洞源于允许攻击者利用用户提供的路径信息验证不足,从而利用可用服务中的路径遍历漏洞删除系统文件。以下产品和版本受到影响:SAP NetWeaver AS 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 7
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | NetWeaver AS for ABAP and ABAP Platform | 700 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25616 | 9.9 CRITICAL | Code Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC) |
| CVE-2023-23857 | 9.9 CRITICAL | Improper Access Control in SAP NetWeaver AS for Java |
| CVE-2023-27500 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27269 | 9.6 CRITICAL | Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-25617 | 9.0 CRITICAL | OS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform |
| CVE-2023-27893 | 8.8 HIGH | Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI) |
| CVE-2023-26459 | 7.4 HIGH | Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Pla |
| CVE-2023-27498 | 7.2 HIGH | Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL) |
| CVE-2023-25615 | 6.8 MEDIUM | SQL Injection vulnerability in SAP ABAP Platform |
| CVE-2023-26461 | 6.8 MEDIUM | XML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal) |
| CVE-2023-27896 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-27271 | 6.5 MEDIUM | Server Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo |
| CVE-2023-27270 | 6.5 MEDIUM | Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-25618 | 6.5 MEDIUM | Denial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27895 | 6.1 MEDIUM | Information Disclosure vulnerability in SAP Authenticator for Android |
| CVE-2023-26457 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Content Server |
| CVE-2023-27268 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Object Analyzing Service) |
| CVE-2023-26460 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Cache Management Service) |
| CVE-2023-24526 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Classload Service) |
| CVE-2023-27894 | 5.0 MEDIUM | Sensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platform |
No comments yet