SAPControl ListConfigFiles - Disclosure
Detected SAP systems where the SAP Start Service (sapstartsrv) SAPControl SOAP interface exposes the ListConfigFiles web method without authentication.
共找到 5 条公开漏洞记录
Detected SAP systems where the SAP Start Service (sapstartsrv) SAPControl SOAP interface exposes the ListConfigFiles web method without authentication.
Detected SAP systems where the SAPControl SOAP web service exposes the ABAPReadSyslog operation without authentication. ABAPReadSyslog returns the ABAP system log (equivalent to transaction SM21) via SAPControl sapstartsrv and includes fields such as client, username, transaction code, message number, free-text message and severity.
Detected SAP systems where the SAP Start Service (sapstartsrv) SAPControl SOAP web service exposes the GetEnvironment web method without authentication.
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.