SAP Financial Consolidation是德国思爱普(SAP)公司的一套财务报表解决方案。该产品主要用于自动化公司间对账和抵销、货币换算并提供财务报表生成等功能。 SAP Financial Consolidation存在安全漏洞,该漏洞源于允许经过身份验证的攻击者通过终止会话断开其他用户连接,暂时阻止访问,对可用性有低影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Financial Consolidation | FINANCE 1010 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Financial Consolidation | FINANCE 1010 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34263 | 9.6 CRITICAL | Missing authentication check in SAP Commerce cloud configuration |
| CVE-2026-34260 | 9.6 CRITICAL | SQL injection vulnerability in SAP S/4HANA (SAP Enterprise Search for ABAP) |
| CVE-2026-34259 | 8.2 HIGH | OS Command Injection Vulnerability in SAP Forecasting & Replenishment |
| CVE-2026-40135 | 6.5 MEDIUM | OS Command Injection vulnerability in SAP NetWeaver Application Server for ABAP and ABAP P |
| CVE-2026-40133 | 6.3 MEDIUM | Missing Authorization check in SAP S/4HANA Condition Maintenance |
| CVE-2026-40137 | 6.1 MEDIUM | Cross-Site Scripting (XSS) vulnerability in Business Server Pages Application (TAF_APPLAUN |
| CVE-2026-0502 | 5.4 MEDIUM | Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform |
| CVE-2026-40132 | 5.4 MEDIUM | Missing Authorization Check in SAP Strategic Enterprise Management (BSP application Balanc |
| CVE-2026-27682 | 4.7 MEDIUM | Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABA |
| CVE-2026-34258 | 4.7 MEDIUM | Content Spoofing vulnerability in SAPUI5 (Search UI) |
| CVE-2026-40129 | 4.3 MEDIUM | Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Pla |
| CVE-2026-40134 | 4.3 MEDIUM | Missing Authorization Check in SAP Incentive and Commission Management |
| CVE-2026-40131 | 3.4 LOW | SQL Injection vulnerability in SAP HANA Deployment Infrastructure (HDI) deploy library |
No comments yet