SAP Adobe Document Service(SAP ADS)是德国思爱普(SAP)公司的一个文档管理服务。 SAP Adobe Document Service存在安全漏洞,该漏洞源于经过管理员身份验证的攻击者,可以使用公开的 Web 服务,在系统服务器上上传或下载自定义 PDF 字体文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver AS for JAVA (Adobe Document Services) | ADSSSAP 7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47578 | 9.1 CRITICAL | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-54198 | 8.5 HIGH | Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver A |
| CVE-2024-54197 | 7.2 HIGH | Server-Side Request Forgery in SAP NetWeaver Administrator (System Overview) |
| CVE-2024-47580 | 6.8 MEDIUM | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-47582 | 5.3 MEDIUM | XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA |
| CVE-2024-32732 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform |
| CVE-2024-47585 | 4.3 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-47581 | 4.3 MEDIUM | Missing Authorization check in SAP HCM (Approve Timesheets version 4) |
| CVE-2024-47576 | 3.3 LOW | DLL Hijacking vulnerability in SAP Product Lifecycle Costing |
| CVE-2024-47577 | 2.7 LOW | Information Disclosure vulnerability in SAP Commerce Cloud |
No comments yet