Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

POC Details: eae65c210947bcb913f1ec806307baf463f503d6

Source
Associated Vulnerability

Likely 0-day

Description
Detected SAP systems where the SAPControl SOAP web service exposes the ABAPReadSyslog operation without authentication. ABAPReadSyslog returns the ABAP system log (equivalent to transaction SM21) via SAPControl sapstartsrv and includes fields such as client, username, transaction code, message number, free-text message and severity.
File Snapshot

id: sap-abapreadsyslog-disclosure info: name: SAPControl ABAPReadSyslog - Disclosure author: LR ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.