SAP HCM Travel Management是德国思爱普(SAP)公司的一个差旅管理模块。 SAP HCM Travel Management 存在跨站脚本漏洞,该漏洞源于未对用户的输入进行充分编码,导致存在跨站脚本(XSS)漏洞。受影响的产品和版本:SAP HCM S4HCMCIE 100版本,SAP_HRCIE 600版本,SAP_HRC IE 604版本,SAP_HRCIE 608版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP HCM (SMART PAYE solution) | S4HCMCIE 100 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49583 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Node.js] @sap/ |
| CVE-2023-50422 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-se |
| CVE-2023-50423 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Python] cloud- |
| CVE-2023-50424 | 9.1 CRITICAL | Escalation of Privileges in SAP BTP Security Services Integration Library ([Golang] github |
| CVE-2023-42481 | 8.1 HIGH | Improper Access Control vulnerability in SAP Commerce Cloud |
| CVE-2023-42478 | 7.5 HIGH | Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Plat |
| CVE-2023-49580 | 7.3 HIGH | Information disclosure in SAP GUI for Windows and SAP GUI for Java |
| CVE-2023-6542 | 7.1 HIGH | Improper Export of Android Application Components in SAP EMARSYS SDK ANDROID |
| CVE-2023-42476 | 6.8 MEDIUM | Cross Site Scripting vulnerability in SAP BusinessObjects Web Intelligence |
| CVE-2023-49587 | 6.4 MEDIUM | Command Injection vulnerability in SAP Solution Manager |
| CVE-2023-42479 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP Biller Direct |
| CVE-2023-49584 | 4.3 MEDIUM | Client-Side Desynchronization vulnerability in SAP Fiori Launchpad |
| CVE-2023-49581 | 4.1 MEDIUM | SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform |
| CVE-2023-49058 | 3.5 LOW | Directory Traversal vulnerability in SAP Master Data Governance |
| CVE-2023-49578 | 3.5 LOW | Denial of service (DOS) in SAP Cloud Connector |
No comments yet