漏洞标题
SAP CRM 中的代码注入漏洞
漏洞描述信息
SAP CRM中的代码注入漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
漏洞类别
N/A
漏洞标题
Code Injection vulnerability in SAP CRM
漏洞描述信息
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
漏洞类别
对生成代码的控制不恰当(代码注入)
漏洞标题
SAP CRM 代码注入漏洞
漏洞描述信息
SAP CRM是德国思爱普(SAP)公司的一个客户关系管理系统。 SAP CRM 700版本、701版本、702版本、712版本、713版本存在代码注入漏洞。攻击者利用该漏洞导致数据的机密性和完整性以及可用性受到影响。
CVSS信息
N/A
漏洞类别
代码注入