漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit)
Vulnerability Description
The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound delivery details. This vulnerability has a low impact on the confidentiality with no effect on the integrity and the availability of the application.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP Electronic Invoicing 安全漏洞
Vulnerability Description
SAP Electronic Invoicing是德国思爱普(SAP)公司的一款电子发票管理解决方案。用于企业电子发票的开具、记账、清账、对账等业务。 SAP Electronic Invoicing存在安全漏洞,该漏洞源于未经授权的访问,可能导致查看入站交付详细信息。
CVSS Information
N/A
Vulnerability Type
N/A