SAP S4CORE是德国思爱普(SAP)公司的一个管理采购合同应用程序。 SAP S4CORE (Manage Purchase Contracts App) 102、103、104、105、106、107版本存在安全漏洞,该漏洞源于不会对经过身份验证的用户执行必要的授权检查,允许攻击者执行意外的操作,从而导致权限升级。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Manage Purchase Contracts App | S4CORE 102 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40622 | 9.9 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-40309 | 9.8 CRITICAL | Missing Authorization check in SAP CommonCryptoLib |
| CVE-2023-42472 | 8.7 HIGH | Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (W |
| CVE-2023-40308 | 7.5 HIGH | Memory Corruption vulnerability in SAP CommonCryptoLib |
| CVE-2023-40621 | 6.3 MEDIUM | Code Injection vulnerability in SAP PowerDesigner Client |
| CVE-2023-40623 | 6.2 MEDIUM | Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer) |
| CVE-2023-40624 | 5.5 MEDIUM | Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rende |
| CVE-2023-41367 | 5.3 MEDIUM | Missing Authentication check in SAP NetWeaver (Guided Procedures) |
| CVE-2023-37489 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-41369 | 3.5 LOW | External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application) |
| CVE-2023-41368 | 2.7 LOW | Insecure Direct Object Reference (IDOR) vulnerability in S4 HANA (Manage checkbook apps) |
No comments yet