Lucene search

K
cvelistSapCVELIST:CVE-2023-32115
HistoryJun 13, 2023 - 2:42 a.m.

CVE-2023-32115 SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)

2023-06-1302:42:28
CWE-89
sap
www.cve.org
sql injection
mds compare tool
attacker
database commands
information retrieval

4.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Master Data Synchronization (MDS COMPARE TOOL)",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_APPL 600"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 602"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 603"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 604"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 605"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 606"
      },
      {
        "status": "affected",
        "version": "SAP_APPL 616"
      }
    ]
  }
]

4.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVELIST:CVE-2023-32115