漏洞标题
SAP NetWeaver (ABAP类生成器)缺少授权检查
漏洞描述信息
由于缺少授权检查,SAP NetWeaver(ABAP类生成器)允许攻击者获得比其应有的更高访问权限,从而导致权限提升。成功利用此漏洞可能导致高敏感信息泄露。此外,这可能对应用程序的完整性和可用性造成严重影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
授权机制缺失
漏洞标题
Missing Authorization check in SAP NetWeaver (ABAP Class Builder)
漏洞描述信息
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a high impact on the integrity and availability of the application.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
授权机制缺失