SAP Forecasting and Replenishment是德国思爱普(SAP)公司的一个面向零售与供应链场景的需求预测与库存补货管理系统。 SAP Forecasting and Replenishment存在命令注入漏洞,该漏洞源于OS命令执行漏洞,可能导致经过身份验证的管理员滥用非远程启用功能执行任意操作系统命令,从而读取或修改系统数据或关闭系统,导致机密性、完整性和可用性完全受损。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Forecasting & Replenishment | SCM 702 |
affected |
712 |
affected | ||
713 |
affected | ||
714 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Forecasting & Replenishment | SCM 702 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34263 | 9.6 CRITICAL | Missing authentication check in SAP Commerce cloud configuration |
| CVE-2026-34260 | 9.6 CRITICAL | SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) |
| CVE-2026-40135 | 6.5 MEDIUM | OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP P |
| CVE-2026-40133 | 6.3 MEDIUM | Missing Authorization check in SAP S/4HANA Condition Maintenance |
| CVE-2026-40137 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUN |
| CVE-2026-0502 | 5.4 MEDIUM | Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform |
| CVE-2026-40132 | 5.4 MEDIUM | Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanc |
| CVE-2026-27682 | 4.7 MEDIUM | Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABA |
| CVE-2026-34258 | 4.7 MEDIUM | Content Spoofing vulnerability in SAPUI5 (Search UI) |
| CVE-2026-40136 | 4.3 MEDIUM | Denial of service (DoS) in SAP Financial Consolidation |
| CVE-2026-40129 | 4.3 MEDIUM | Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Pla |
| CVE-2026-40134 | 4.3 MEDIUM | Missing Authorization Check in SAP Incentive and Commission Management |
| CVE-2026-40131 | 3.4 LOW | SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library |
No comments yet