Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library
Vulnerability Description
SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability of the application. There is no impact on integrity.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
SAP HANA Deployment Infrastructure deploy library SQL注入漏洞
Vulnerability Description
SAP HANA Deployment Infrastructure deploy library是德国思爱普(SAP)公司的一个面向 SAP HANA 应用部署与生命周期管理的部署支持库。 SAP HANA Deployment Infrastructure deploy library存在SQL注入漏洞,该漏洞源于SQL查询使用用户输入动态构建且未正确参数化或使用预编译语句,可能导致高权限用户修改SELECT语句,影响机密性和可用性。
CVSS Information
N/A
Vulnerability Type
N/A