SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver 7.50版本存在访问控制错误漏洞,该漏洞源于webdynpro应用程序中缺少身份验证检查,导致未经授权的攻击者可以匿名访问特定功能的管理员视图。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver (Guided Procedures) | 7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40622 | 9.9 CRITICAL | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-40309 | 9.8 CRITICAL | Missing Authorization check in SAP CommonCryptoLib |
| CVE-2023-42472 | 8.7 HIGH | Insufficient File type validation in SAP BusinessObjects Business Intelligence Platform (W |
| CVE-2023-40308 | 7.5 HIGH | Memory Corruption vulnerability in SAP CommonCryptoLib |
| CVE-2023-40621 | 6.3 MEDIUM | Code Injection vulnerability in SAP PowerDesigner Client |
| CVE-2023-40623 | 6.2 MEDIUM | Arbitrary File Delete via Directory Junction in SAP BusinessObjects Suite(installer) |
| CVE-2023-40624 | 5.5 MEDIUM | Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rende |
| CVE-2023-40625 | 5.4 MEDIUM | Missing Authorization check in SAP Manage Purchase Contracts App |
| CVE-2023-37489 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2023-41369 | 3.5 LOW | External Entity Loop vulnerability in SAP S/4HANA (Create Single Payment application) |
| CVE-2023-41368 | 2.7 LOW | Insecure Direct Object Reference (IDOR) vulnerability in S4 HANA (Manage checkbook apps) |
No comments yet