SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver (BI CONT ADDON) 707、737、747、757版本存在路径遍历漏洞,攻击者利用该漏洞可以上传和覆盖 SAP 服务器上的文件,从而使系统不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP | NetWeaver (BI CONT ADDON) | 707 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-27497 | 10.0 CRITICAL | Multiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector) |
| CVE-2023-28765 | 9.8 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-27267 | 9.0 CRITICAL | Multiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge) |
| CVE-2023-26458 | 6.8 MEDIUM | Information Disclosure vulnerability in SAP Landscape Management |
| CVE-2023-29187 | 6.7 MEDIUM | DLL Hijacking vulnerability in SapSetup (Software Installation Program) |
| CVE-2023-28761 | 6.5 MEDIUM | Missing Authentication check in SAP NetWeaver Enterprise Portal |
| CVE-2023-28763 | 6.5 MEDIUM | Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform |
| CVE-2023-27897 | 6.0 MEDIUM | Code Injection vulnerability in SAP CRM |
| CVE-2023-29189 | 5.4 MEDIUM | HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI) |
| CVE-2023-24527 | 5.3 MEDIUM | Improper Access Control in SAP NetWeaver AS Java for Deploy Service |
| CVE-2023-29185 | 5.3 MEDIUM | Denial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages) |
| CVE-2023-29108 | 5.0 MEDIUM | IP filter vulnerability in ABAP Platform and SAP Web Dispatcher |
| CVE-2023-29109 | 4.4 MEDIUM | Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard) |
| CVE-2023-1903 | 4.3 MEDIUM | Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0) |
| CVE-2023-29110 | 3.7 LOW | Code Injection vulnerability in SAP Application Interface Framework (Message Dashboard) |
| CVE-2023-29112 | 3.7 LOW | Code Injection vulnerability in SAP Application Interface Framework (Message Monitoring) |
| CVE-2023-29111 | 3.1 LOW | Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service |
No comments yet