漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA
Vulnerability Description
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
SAP Human Capital Management 安全漏洞
Vulnerability Description
SAP Human Capital Management是德国思爱普(SAP)公司的一个企业人力资源管理与员工生命周期管理系统。 SAP Human Capital Management存在安全漏洞,该漏洞源于授权检查期间系统返回特定消息,可能导致低权限认证用户猜测和枚举超出其授权范围的内容,泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A