Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger)
Vulnerability Description
Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
SAP S/4HANA Private Cloud and On-Premise SQL注入漏洞
Vulnerability Description
SAP S/4HANA Private Cloud and On-Premise是德国思爱普(SAP)公司的一个服务本地部署方案。 SAP S/4HANA Private Cloud and On-Premise存在SQL注入漏洞,该漏洞源于输入验证不足,可能导致已验证用户执行特制SQL查询以读取、修改和删除后端数据库数据,对应用程序机密性、完整性和可用性造成高影响。
CVSS Information
N/A
Vulnerability Type
N/A