SAP NetWeaver AS是德国思爱普(SAP)公司的一款SAP网络应用服务器。它不仅能提供网络服务,且还是SAP软件的基本平台。 SAP NetWeaver AS ABAP (applications based on Unified Rendering) SAP_UI 754、SAP_UI 755、SAP_UI 756、SAP_UI 757、SAP_UI 758、SAP_BASIS 702、SAP_BASIS 731版本存在跨站脚本漏洞,该漏洞源于允许攻击者在 Web 应用程序中执行的 Java
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver AS ABAP (applications based on Unified Rendering) | SAP_UI 754 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40622 | 9.9 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-40309 | 9.8 CRITICAL | Missing Authorization check in SAP CommonCryptoLib |
| CVE-2023-42472 | 8.7 HIGH | Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (W |
| CVE-2023-40308 | 7.5 HIGH | Memory Corruption vulnerability in SAP CommonCryptoLib |
| CVE-2023-40621 | 6.3 MEDIUM | Code Injection vulnerability in SAP PowerDesigner Client |
| CVE-2023-40623 | 6.2 MEDIUM | Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer) |
| CVE-2023-40625 | 5.4 MEDIUM | Missing Authorization check in SAP Manage Purchase Contracts App |
| CVE-2023-41367 | 5.3 MEDIUM | Missing Authentication check in SAP NetWeaver (Guided Procedures) |
| CVE-2023-37489 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-41369 | 3.5 LOW | External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application) |
| CVE-2023-41368 | 2.7 LOW | Insecure Direct Object Reference (IDOR) vulnerability in S4 HANA (Manage checkbook apps) |
No comments yet