Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)
Vulnerability Description
SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
暴露危险的方法或函数
Vulnerability Title
SAP BTP Security Services Integration Library 安全漏洞
Vulnerability Description
SAP BTP Security Services Integration Library是德国思爱普(SAP)公司的一个安全服务集成库。 SAP BTP Security Services Integration Library 2.17.0 之前、 3.3.0之前版本存在安全漏洞,该漏洞源于允许在某些条件下升级权限,攻击者利用该漏洞可以获得应用程序内的任意权限。
CVSS Information
N/A
Vulnerability Type
N/A