SAP Plant Connectivity是德国思爱普(SAP)公司的一个设备和 MES 之间的桥梁,用于标准数据源之间交换数据。 SAP Plant Connectivity 15.5版本和SAP Digital Manufacturing 1.0版本存在访问控制错误漏洞,该漏洞源于没有验证HTTP请求中的 JWT签名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Plant Connectivity | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-33991 | 8.2 HIGH | Stored Cross-Site Scripting (Stored XSS) vulnerability in SAP UI5 Variant Management |
| CVE-2023-33984 | 6.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in NetWeaver (Design Time Repository) |
| CVE-2023-33985 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2023-33986 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP CRM ABAP (Grantor Management) |
| CVE-2023-32115 | 4.2 MEDIUM | SQL Injection in Master Data Synchronization (MDS COMPARE TOOL) |
| CVE-2023-32114 | 2.7 LOW | Denial of Service in SAP NetWeaver |
No comments yet