疑似 0-day
Detected SAP systems where the SAP Start Service (sapstartsrv) SAPControl SOAP interface exposes the ReadConfigFile web method in combination with an unprotected ListConfigFiles call, allowing unauthenticated reading of the global DEFAULT.PFL profile.
id: sap-readconfig-disclosure
info:
name: SAPControl Read DEFAULT.PFL - Disclosure
author: LRVT
...