目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2023-27894— SAP BusinessObjects Business Intelligence Platform 信息泄露漏洞

CVSS 5.0 · Medium EPSS 0.62% · P46
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-27894の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Sensitive Information Disclosure in the SAP BusinessObjects Business Intelligence platform
ソース: CVE Program / CVE List V5
脆弱性説明
SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker can scan internal network to determine internal infrastructure for further attacks like remote file inclusion, retrieve server files, bypass firewall and force the vulnerable server to execute malicious requests, resulting in sensitive information disclosure. This causes limited impact on confidentiality of data.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
信息暴露
ソース: CVE Program / CVE List V5
脆弱性タイトル
SAP BusinessObjects Business Intelligence Platform 信息泄露漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
SAP BusinessObjects Business Intelligence Platform是德国思爱普(SAP)公司的一款完备的商务分析平台。该平台集市场领先的 SAP 数据整合产品、数据管理产品和商务智能 (BI) 产品于一身,可消除系统集成难题,快速、轻松地部署高性能的商务分析软件。 SAP BusinessObjects Business Intelligence Platform 420版本和430版本存在信息泄露漏洞,该漏洞源于允许攻击者注入任意值作为CMS参数以在内部网络上执行查找,
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
SAPBusinessObjects Business Intelligence Platform (Web Services) 420 -

II. CVE-2023-27894の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-27894のインテリジェンス情報

登录查看更多情报信息。

CVE-2023-27894 其他参考 (1)

Same Patch Batch · SAP · 2023-03-14 · 21 CVEs total

CVE-2023-256169.9 CRITICALCode Injection vulnerability in SAP Business Objects Business Intelligence Platform (CMC)
CVE-2023-238579.9 CRITICALImproper Access Control in SAP NetWeaver AS for Java
CVE-2023-275009.6 CRITICALDirectory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-272699.6 CRITICALDirectory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-256179.0 CRITICALOS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform
CVE-2023-278938.8 HIGHArbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)
CVE-2023-275018.7 HIGHDirectory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-264597.4 HIGHServer Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Pla
CVE-2023-274987.2 HIGHMemory Corruption vulnerability in SAP Host Agent (SAPOSCOL)
CVE-2023-264616.8 MEDIUMXML External Entity (XXE) vulnerability in SAP NetWeaver (SAP Enterprise Portal)
CVE-2023-256156.8 MEDIUMSQL Injection vulnerability in SAP ABAP Platform
CVE-2023-272706.5 MEDIUMDenial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-272716.5 MEDIUMServer Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo
CVE-2023-256186.5 MEDIUMDenial of Service (DoS) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CVE-2023-278966.5 MEDIUMServer Side Request Forgery (SSRF) in the SAP BusinessObjects Business Intelligence platfo
CVE-2023-278956.1 MEDIUMInformation Disclosure vulnerability in SAP Authenticator for Android
CVE-2023-264576.1 MEDIUMCross-Site Scripting (XSS) vulnerability in SAP Content Server
CVE-2023-272685.3 MEDIUMImproper Access Control in SAP NetWeaver AS Java (Object Analyzing Service)
CVE-2023-264605.3 MEDIUMImproper Access Control in SAP NetWeaver AS Java (Cache Management Service)
CVE-2023-245265.3 MEDIUMImproper Access Control in SAP NetWeaver AS Java (Classload Service)

IV. 関連脆弱性

V. CVE-2023-27894へのコメント

まだコメントはありません


コメントを残す