Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Vulnerability Description
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP NetWeaver Application Server 安全漏洞
Vulnerability Description
SAP NetWeaver Application Server是德国思爱普(SAP)公司的一款应用程序服务器。 SAP NetWeaver Application Server for ABAP存在安全漏洞,该漏洞源于支持 RFC 的功能模块允许低权限用户执行各种操作,例如修改任何用户最喜欢的节点的 URL 和工作簿 ID。
CVSS Information
N/A
Vulnerability Type
N/A