SAP Business One是德国思爱普(SAP)公司的一套企业管理软件。该软件包括财务管理、运营管理和人力资源管理等功能。 SAP Business One 10.0版本存在安全漏洞,该漏洞源于允许授权攻击者检索故障消息的详细堆栈跟踪以进行XXE注入,导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Business One (B1i) | 10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-42474 | 6.8 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Web Intelligence |
| CVE-2023-42477 | 6.5 MEDIUM | Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application) |
| CVE-2023-40310 | 6.5 MEDIUM | Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import |
| CVE-2023-42473 | 5.4 MEDIUM | Missing Authorization Check In S/4HANA (Manage Withholding Tax Items) |
| CVE-2023-42475 | 4.3 MEDIUM | Information Disclosure Vulnerability in Statutory Reporting |
No comments yet