漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow
Vulnerability Description
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
SAP Business Workflow和SAP Flexible Workflow 安全漏洞
Vulnerability Description
SAP Business Workflow和SAP Flexible Workflow都是德国思爱普(SAP)公司的产品。SAP Business Workflow是用于执行业务流程的关键组件,它允许用户设计、实施和管理业务流程,确保流程的合规性,并通过自动化减少手动操作的需要。SAP Flexible Workflow是一个灵活工作流程管理程序。 SAP Business Workflow和SAP Flexible Workflow存在安全漏洞,该漏洞源于经过身份验证的攻击者可以操纵合法资源请求中的参数
CVSS Information
N/A
Vulnerability Type
N/A