CVE-2024-33009
SQL injection vulnerability in SAP Global Label Management (GLM)
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.2EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
14 may 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Productos afectados
SAP_SE · SAP Global Label Management (GLM)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →