漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authentication bypass via authorization code injection in SAP Approuter
Vulnerability Description
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
CWE-1287
Vulnerability Title
SAP Approuter 输入验证错误漏洞
Vulnerability Description
SAP Approuter是德国思爱普(SAP)公司的一项轻量级服务,可作为 SAP 生态系统中各种后端服务和应用程序的单一入口点。 SAP Approuter v16.7.1版本及之前版本存在输入验证错误漏洞。攻击者利用该漏洞可以通过注入恶意载荷来窃取受害者的会话。
CVSS Information
N/A
Vulnerability Type
N/A