Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
Vulnerability Description
An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP CRM和SAP S/4HANA 安全漏洞
Vulnerability Description
SAP CRM和SAP S/4HANA都是德国思爱普(SAP)公司的产品。SAP CRM是一个客户关系管理系统。SAP S/4HANA是一个基于 SAP HANA 内存数据库系统的的企业资源管理软件。 SAP CRM和SAP S/4HANA存在安全漏洞,该漏洞源于通用功能模块调用存在缺陷,可能导致执行任意SQL语句和完全数据库破解。
CVSS Information
N/A
Vulnerability Type
N/A