Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-26458— Information Disclosure vulnerability in SAP Landscape Management

CVSS 6.8 · Medium EPSS 0.34% · P56
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-26458

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Information Disclosure vulnerability in SAP Landscape Management
Source: NVD (National Vulnerability Database)
Vulnerability Description
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information is for Diagnostics Agent Connection via Java SCS Message Server of an SAP Solution Manager system and can only be accessed by authenticated SAP Landscape Management users, but they can escalate their privileges to the SAP Solution Manager system.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
将资源暴露给错误范围
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP Landscape Management 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP Landscape Management是德国思爱普(SAP)公司的一套SAP产品集中管理系统。该系统主要用于集中管理和配置在物理、虚拟和云基础架构中运行的SAP软件系统。 SAP Landscape Management 3.0版本存在安全漏洞。攻击者利用该漏洞可以提升权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SAPLandscape Management 3.0 -

II. Public POCs for CVE-2023-26458

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-26458

登录查看更多情报信息。

Same Patch Batch · SAP · 2023-04-11 · 18 CVEs total

CVE-2023-2749710.0 CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)
CVE-2023-287659.8 CRITICALInformation Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform
CVE-2023-272679.0 CRITICALMultiple vulnerabilities in SAP Diagnostics Agent (OSCommand Bridge)
CVE-2023-291868.7 HIGHDirectory/Path Traversal vulnerability in SAP NetWeaver.
CVE-2023-291876.7 MEDIUMDLL Hijacking vulnerability in SapSetup (Software Installation Program)
CVE-2023-287616.5 MEDIUMMissing Authentication check in SAP NetWeaver Enterprise Portal
CVE-2023-287636.5 MEDIUMDenial of Service in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-278976.0 MEDIUMCode Injection vulnerability in SAP CRM
CVE-2023-291895.4 MEDIUMHTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
CVE-2023-291855.3 MEDIUMDenial of Service (DOS) in SAP NetWeaver AS for ABAP (Business Server Pages)
CVE-2023-245275.3 MEDIUMImproper Access Control in SAP NetWeaver AS Java for Deploy Service
CVE-2023-291085.0 MEDIUMIP filter vulnerability in ABAP Platform and SAP Web Dispatcher
CVE-2023-291094.4 MEDIUMCode Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
CVE-2023-19034.3 MEDIUMMissing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0)
CVE-2023-291103.7 LOWCode Injection vulnerability in SAP Application Interface Framework (Message Dashboard)
CVE-2023-291123.7 LOWCode Injection vulnerability in SAP Application Interface Framework (Message Monitoring)
CVE-2023-291113.1 LOWInformation Disclosure vulnerability in SAP Application Interface Framework (ODATA service

IV. Related Vulnerabilities

V. Comments for CVE-2023-26458

No comments yet


Leave a comment