SAP CRM是德国思爱普(SAP)公司的一个客户关系管理系统。 SAP CRM存在跨站脚本漏洞,该漏洞源于输入验证不足,允许未经身份验证的攻击者制作嵌入恶意脚本的URL链接能够访问和/或修改信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP CRM WebClient UI | S4FND 102 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-37177 | 8.1 HIGH | Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation |
| CVE-2024-34688 | 7.5 HIGH | Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository) |
| CVE-2024-33001 | 6.5 MEDIUM | Denial of service (DOS) in SAP NetWeaver and ABAP platform |
| CVE-2024-34683 | 6.5 MEDIUM | Unrestricted file upload in SAP Document Builder (HTTP service) |
| CVE-2024-34691 | 6.5 MEDIUM | Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files) |
| CVE-2024-37176 | 5.5 MEDIUM | Missing Authorization check in SAP BW/4HANA Transformation and DTP |
| CVE-2024-34690 | 5.4 MEDIUM | Missing Authorization check in SAP Student Life Cycle Management (SLcM) |
| CVE-2024-28164 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures) |
| CVE-2024-37178 | 5.0 MEDIUM | Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation |
| CVE-2024-34684 | 3.7 LOW | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
No comments yet