SAP揭露重大層級漏洞,攻擊者可趁機繞過身分驗證
支付動態 · 2024-08-14

本週二SAP發布8月例行更新,其中修補2個重大層級漏洞,而最嚴重的漏洞CVE-2024-41730,有機會讓攻擊者從REST端點竊得憑證,甚至有機會完全控制商業智慧平臺BusinessObjects

本月SAP例行更新於8月13日發布,該公司總共修補17個漏洞,其中有2個為重大層級,4個為高風險層級,其餘漏洞的危險程度則列為中度風險。

根據CVSS風險評分,最嚴重的漏洞是CVE-2024-41730,此漏洞出現於商業智慧平臺BusinessObjects,起因是缺乏身分驗證的檢核,這項問題出現在啟用單一簽入(SSO)的企業環境,攻擊者可在未經身分驗證的情況下,利用REST端點竊得登入系統的憑證(Token),CVSS風險評為9.8分,影響430、440版系統。

SAP指出,攻擊者若成功利用漏洞,可能得以完全入侵該系統,從而嚴重影響系統的機密性、完整性,以及可用性。

另一個重大層級漏洞是CVE-2024-29415,此漏洞發生在SAP Build Apps打造的應用程式,為伺服器請求偽造(SSRF)漏洞,CVSS風險評為9.1。

這項漏洞涉及Node.js的IP元件缺陷,此元件用途是檢查IP位址是公開或是私有,在使用8進位表示127.0.0.1的時候,會將其識別為公開且全域可路由的IP位址。SAP指出,這項漏洞是先前另一個弱點CVE-2023-42282修補不全所致。

熱門文章
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Indiana online casino bill stalls in House committee
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
PropellerAds Positions Itself as a Go-To Traffic Source for iGaming Advertisers Ahead of a High-Demand Season
Marketing
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
British gambling levy rates confirmed for each vertical
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
That’s a Wrap: AffPapa Conference Madrid 2026 Highlights
Online Game
Manila delivers: Highlights from SiGMA Asia 2026 
Southeast Asia
Global Game Connect (GGC) 2027 Officially Opens Sponsorship & Exhibition Opportunities in Sri Lanka!
HUIDU Focus
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
首頁
遊戲
合作
發現
我的