SAP NetWeaver Administrator(SAP NWA)是德国思爱普(SAP)公司的一个基于 Web 的框架工具,用于管理、配置和监控。 SAP NetWeaver Administrator存在代码问题漏洞,该漏洞源于允许经过身份验证的攻击者通过特制的 HTTP 请求枚举内部网络中可访问的 HTTP 端点,容易受到服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver Administrator(System Overview) | LM-CORE 7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47578 | 9.1 CRITICAL | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-54198 | 8.5 HIGH | Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver A |
| CVE-2024-47580 | 6.8 MEDIUM | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-47579 | 6.8 MEDIUM | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-47582 | 5.3 MEDIUM | XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA |
| CVE-2024-32732 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform |
| CVE-2024-47585 | 4.3 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-47581 | 4.3 MEDIUM | Missing Authorization check in SAP HCM (Approve Timesheets version 4) |
| CVE-2024-47576 | 3.3 LOW | DLL Hijacking vulnerability in SAP Product Lifecycle Costing |
| CVE-2024-47577 | 2.7 LOW | Information Disclosure vulnerability in SAP Commerce Cloud |
No comments yet