SAP Financial Consolidation是德国思爱普(SAP)公司的一套财务报表解决方案。该产品主要用于自动化公司间对账和抵销、货币换算并提供财务报表生成等功能。 SAP Financial Consolidation FINANCE 1010版本存在跨站脚本漏洞,该漏洞源于允许通过不可信的来源输入数据,这些端点在网络上暴露,允许用户修改网站内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Financial Consolidation | FINANCE 1010 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-34688 | 7.5 HIGH | Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository) |
| CVE-2024-33001 | 6.5 MEDIUM | Denial of service (DOS) in SAP NetWeaver and ABAP platform |
| CVE-2024-34683 | 6.5 MEDIUM | Unrestricted file upload in SAP Document Builder (HTTP service) |
| CVE-2024-34691 | 6.5 MEDIUM | Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files) |
| CVE-2024-34686 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI) |
| CVE-2024-37176 | 5.5 MEDIUM | Missing Authorization check in SAP BW/4HANA Transformation and DTP |
| CVE-2024-34690 | 5.4 MEDIUM | Missing Authorization check in SAP Student Life Cycle Management (SLcM) |
| CVE-2024-28164 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures) |
| CVE-2024-37178 | 5.0 MEDIUM | Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation |
| CVE-2024-34684 | 3.7 LOW | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform |
No comments yet