尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| SAP_SE | SAP S/4HANA (Private Cloud or On-Premise) | S4CORE 102 | - |
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/callinston/CVE-2025-42957 | POC详情 |
| 2 | CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full control. The article explains the vulnerability, threat model, provides minimal exploit ABAP code, and lists patching & monitoring steps to secure the system | https://github.com/mrk336/CVE-2025-42957-SAP-S-4HANA-Under-Siege | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-42950 | 9.9 CRITICAL | SAP Landscape Transformation 代码注入漏洞 |
| CVE-2025-42951 | 8.8 HIGH | SAP Business One 安全漏洞 |
| CVE-2025-42976 | 8.1 HIGH | SAP NetWeaver Application Server ABAP 缓冲区错误漏洞 |
| CVE-2025-42946 | 6.9 MEDIUM | SAP S/4HANA 路径遍历漏洞 |
| CVE-2025-42975 | 6.1 MEDIUM | SAP NetWeaver Application Server ABAP 跨站脚本漏洞 |
| CVE-2025-42948 | 6.1 MEDIUM | SAP NetWeaver ABAP Platform 跨站脚本漏洞 |
| CVE-2025-42945 | 6.1 MEDIUM | SAP NetWeaver Application Server ABAP 代码注入漏洞 |
| CVE-2025-42942 | 6.1 MEDIUM | SAP NetWeaver Application Server ABAP 跨站脚本漏洞 |
| CVE-2025-42936 | 5.4 MEDIUM | SAP NetWeaver Application Server ABAP 安全漏洞 |
| CVE-2025-42949 | 4.9 MEDIUM | SAP ABAP Platform 安全漏洞 |
| CVE-2025-42943 | 4.5 MEDIUM | SAP GUI for Windows 安全漏洞 |
| CVE-2025-42934 | 4.3 MEDIUM | SAP S/4HANA 注入漏洞 |
| CVE-2025-42935 | 4.1 MEDIUM | SAP Internet Communication Manager和SAP NetWeaver Application Server ABAP 日志信息泄露漏洞 |
| CVE-2025-42955 | 3.5 LOW | SAP Cloud Connector 安全漏洞 |
| CVE-2025-42941 | 3.5 LOW | SAP Fiori 安全漏洞 |
暂无评论