SAP

Manufacturing Integration And Intelligence

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 25.93%
  • Veröffentlicht 09.03.2021 15:15:14
  • Zuletzt bearbeitet 05.05.2025 17:16:58

SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashb...

  • EPSS 0.2%
  • Veröffentlicht 15.02.2019 18:29:02
  • Zuletzt bearbeitet 21.11.2024 04:16:36

SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external applicat...

  • EPSS 0.15%
  • Veröffentlicht 24.11.2015 20:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.