SAP Web Dispatcher是德国思爱普(SAP)公司的Load Balancing 的核心组件,支持负载均衡,提供反向代理的功能,使得外网用户可以访问到内部应用。 SAP Web Dispatcher 存在安全漏洞,该漏洞源于在某些情况下,可能允许攻击者访问原本会受到限制的信息,从而对机密性造成严重影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver (Internet Communication Manager) | KERNEL 7.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-21737 | 8.4 HIGH | Code Injection vulnerability in SAP Application Interface Framework (File Adapter) |
| CVE-2024-22125 | 7.4 HIGH | Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connecto |
| CVE-2024-21735 | 7.3 HIGH | Improper Authorization check in SAP LT Replication Server |
| CVE-2024-21736 | 6.4 MEDIUM | Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management) |
| CVE-2024-21738 | 4.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP |
| CVE-2024-21734 | 3.7 LOW | URL Redirection vulnerability in SAP Marketing (Contacts App) |
No comments yet