Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3c75-76g3-hcrx

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

EPSS

Процентиль: 24%
0.00084
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
около 2 месяцев назад

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

CVSS3: 9.9
fstec
2 месяца назад

Уязвимость платформы управления программными средами SAP Solution Manager, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 24%
0.00084
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94