Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Vulnerability Description
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS commands without detection, potentially impacting the integrity and availability of the application, with no impact on confidentiality.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP 命令注入漏洞
Vulnerability Description
SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP都是德国思爱普(SAP)公司的产品。SAP NetWeaver ABAP Platform是一个一体化技术平台。SAP NetWeaver Application Server for ABAP是一个核心应用服务器平台。 SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP存在命令注入
CVSS Information
N/A
Vulnerability Type
N/A