漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
Vulnerability Description
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Vulnerability Type
忘记口令恢复机制弱
Vulnerability Title
SAP NetWeaver 授权问题漏洞
Vulnerability Description
SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver 存在授权问题漏洞,该漏洞源于用户管理引擎中存在安全错误配置。
CVSS Information
N/A
Vulnerability Type
N/A