SAP Production and Revenue Accounting是德国思爱普(SAP)公司的一个综合解决方案,用于高效管理收入会计的关键流程。 SAP Production and Revenue Accounting存在安全漏洞,该漏洞源于缺乏适当的授权检查,SAP 生产和收入会计中过时的 Tobin 接口中的功能模块允许未经授权的访问,从而可能导致高度敏感数据的泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Production and Revenue Accounting (Tobin interface) | S4CEXT 106 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-42378 | 6.1 MEDIUM | Cross-Site Scripting (XSS) in eProcurement on S/4HANA |
| CVE-2024-45279 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP (CRM |
| CVE-2024-45283 | 6.0 MEDIUM | Information disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service) |
| CVE-2024-45281 | 5.8 MEDIUM | DLL hijacking vulnerability in SAP BusinessObjects Business Intelligence Platform |
| CVE-2024-42371 | 5.4 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-45285 | 5.4 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-44117 | 5.4 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-45280 | 4.8 MEDIUM | Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application) |
| CVE-2024-44120 | 4.7 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal |
| CVE-2024-44116 | 4.3 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-44112 | 4.3 MEDIUM | Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution) |
| CVE-2024-44115 | 4.3 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-44121 | 4.3 MEDIUM | Information Disclosure in SAP S/4 HANA (Statutory Reports) |
| CVE-2024-44113 | 4.3 MEDIUM | Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer) |
| CVE-2024-42380 | 4.3 MEDIUM | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-41729 | 4.3 MEDIUM | Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer) |
| CVE-2024-41728 | 2.7 LOW | Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-45284 | 2.4 LOW | Missing authorization check in SAP Student Life Cycle Management (SLcM) |
| CVE-2024-44114 | 2.0 LOW | Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform |
No comments yet