疑似 0-day
Detected SAP systems where the SAPControl SOAP web service exposes the ABAPReadSyslog operation without authentication. ABAPReadSyslog returns the ABAP system log (equivalent to transaction SM21) via SAPControl sapstartsrv and includes fields such as client, username, transaction code, message number, free-text message and severity.
id: sap-abapreadsyslog-disclosure
info:
name: SAPControl ABAPReadSyslog - Disclosure
author: LR
...