Lucene search

K
cve[email protected]CVE-2023-49581
HistoryDec 12, 2023 - 2:15 a.m.

CVE-2023-49581

2023-12-1202:15:07
CWE-89
web.nvd.nist.gov
30
cve-2023-49581
sap
gui
windows
java
unauthenticated access
vulnerability
database table
as abap
availability
nvd

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.2%

SAP GUI for Windowsย andย SAP GUI for Javaย allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.

Affected configurations

NVD
Node
sapnetweaver_application_server_abapMatch700sap_basis
OR
sapnetweaver_application_server_abapMatch731sap_basis
OR
sapnetweaver_application_server_abapMatch740sap_basis
OR
sapnetweaver_application_server_abapMatch750sap_basis

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP NetWeaver Application Server ABAP and ABAP Platform",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_BASIS 700"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS731"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS740"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS750"
      }
    ]
  }
]

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.2%

Related for CVE-2023-49581