SAP NetWeaver AS是德国思爱普(SAP)公司的一款SAP网络应用服务器。它不仅能提供网络服务,且还是SAP软件的基本平台。 SAP NetWeaver AS for ABAP and ABAP Platform 740、750、751、752、753、754、755、756、757、791版本存在资源管理错误漏洞,该漏洞源于允许经过身份验证的攻击者作为非管理用户使用某些参数制作请求,这些参数可以消耗 服务器的资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | NetWeaver AS for ABAP and ABAP Platform | 740 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-27497 | 10.0 CRITICAL | Multiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector) |
| CVE-2023-28765 | 9.8 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-27267 | 9.0 CRITICAL | Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge) |
| CVE-2023-29186 | 8.7 HIGH | Directory/Path Traversal vulnerability in SAP NetWeaver. |
| CVE-2023-26458 | 6.8 MEDIUM | Information Disclosure vulnerability in SAP Landscape Management |
| CVE-2023-29187 | 6.7 MEDIUM | DLL Hijacking vulnerability in SapSetup (Software Installation Program) |
| CVE-2023-28761 | 6.5 MEDIUM | Missing Authentication check in SAP NetWeaver Enterprise Portal |
| CVE-2023-27897 | 6.0 MEDIUM | Code Injection vulnerability in SAP CRM |
| CVE-2023-29189 | 5.4 MEDIUM | HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI) |
| CVE-2023-29185 | 5.3 MEDIUM | Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages) |
| CVE-2023-24527 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java for Deploy Service |
| CVE-2023-29108 | 5.0 MEDIUM | IP filter vulnerability in ABAP Platform and SAP Web Dispatcher |
| CVE-2023-29109 | 4.4 MEDIUM | Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard) |
| CVE-2023-1903 | 4.3 MEDIUM | Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0) |
| CVE-2023-29110 | 3.7 LOW | Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard) |
| CVE-2023-29112 | 3.7 LOW | Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring) |
| CVE-2023-29111 | 3.1 LOW | Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service |
No comments yet