Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP NetWeaver AS Java (Administrator Log Viewer plug-in) | 7.50 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SAP RCE auto-chain (CVE-2024-22127 + DIAG) | https://github.com/mylo-2001/SAPSlayer | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-27902 | 5.4 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP applications based on SA |
| CVE-2024-25645 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal) |
| CVE-2024-28163 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP NetWeaver Process Integration (Support Web Pag |
| CVE-2024-25644 | 5.3 MEDIUM | Information Disclosure vulnerability in NetWeaver (WSRM) |
| CVE-2024-22133 | 4.6 MEDIUM | Improper Access Control in SAP Fiori Front End Server |
| CVE-2024-27900 | 4.3 MEDIUM | Missing Authorization check in SAP ABAP Platform |
No comments yet