Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
Vulnerability Description
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
相对路径遍历
Vulnerability Title
SAP CRM 安全漏洞
Vulnerability Description
SAP CRM是德国思爱普(SAP)公司的一个客户关系管理系统。 SAP CRM (WebClient UI) 存在安全漏洞,该漏洞源于允许攻击者通过网络服务器的请求中修改使用的 HTTP 动词 ,攻击者利用该漏洞可能导致form字段暴露。
CVSS Information
N/A
Vulnerability Type
N/A