SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3392547 | Permissions Required Vendor Advisory |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Dec 2023, 20:03
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:sap_basis:*:*:* cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:sap_basis:*:*:* cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:sap_basis:*:*:* cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:sap_basis:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.4 |
CWE | CWE-89 | |
References | () https://me.sap.com/notes/3392547 - Permissions Required, Vendor Advisory | |
References | () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory |
12 Dec 2023, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-12 02:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-49581
Mitre link : CVE-2023-49581
CVE.ORG link : CVE-2023-49581
JSON object : View
Products Affected
sap
- netweaver_application_server_abap
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')