SAP Master Data Governance是德国思爱普(SAP)公司的一套用于维护、验证和分发主数据的数据管理工具。 SAP Master Data Governance存在路径遍历漏洞,该漏洞源于File Upload功能对用户提供的路径信息验证不足,导致存在路径遍历漏洞。受影响的产品和版本:SAP Master Data Governance 731版本, 732版本, 746版本, 747版本, 748版本, 749版本, 800版本, 751版本, 752版本, 801版本, 802版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Master Data Governance | MDG_FND 731 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49583 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Node.js] @sap/ |
| CVE-2023-50422 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-se |
| CVE-2023-50423 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Python] cloud- |
| CVE-2023-50424 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Golang] github |
| CVE-2023-42481 | 8.1 HIGH | Improper Access Control vulnerability in SAP Commerce Cloud |
| CVE-2023-42478 | 7.5 HIGH | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2023-49580 | 7.3 HIGH | Information disclosure in SAP GUI for Windows and SAP GUI for Java |
| CVE-2023-6542 | 7.1 HIGH | Improper Export of Android Application Components in SAP EMARSYS SDK ANDROID |
| CVE-2023-42476 | 6.8 MEDIUM | Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence |
| CVE-2023-49587 | 6.4 MEDIUM | Command Injection vulnerability in SAP Solution Manager |
| CVE-2023-42479 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct |
| CVE-2023-49577 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in the SAP HCM (SMART PAYE solution) |
| CVE-2023-49584 | 4.3 MEDIUM | Client-Side Desynchronization vulnerability in SAP Fiori Launchpad |
| CVE-2023-49581 | 4.1 MEDIUM | SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform |
| CVE-2023-49578 | 3.5 LOW | Denial of service (DOS) in SAP Cloud Connector |
No comments yet