Lucene search

K
cvelistSapCVELIST:CVE-2023-33992
HistoryJul 11, 2023 - 2:34 a.m.

CVE-2023-33992 Missing Authorization Check in SAP Business Warehouse and SAP BW/4HANA

2023-07-1102:34:11
CWE-862
sap
www.cve.org
5
cve-2023-33992
missing authorization check
sap business warehouse
sap bw/4hana
bics communication layer
unauthorized cell values
data response
exploit
authorizations
query
keyfigure/measure level.

CVSS3

4.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

35.4%

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP Business Warehouse and SAP BW/4HANA",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_BW 730"
      },
      {
        "status": "affected",
        "version": "SAP_BW 731"
      },
      {
        "status": "affected",
        "version": "SAP_BW 740"
      },
      {
        "status": "affected",
        "version": "SAP_BW 750"
      },
      {
        "status": "affected",
        "version": "DW4CORE 100"
      },
      {
        "status": "affected",
        "version": "DW4CORE 200"
      },
      {
        "status": "affected",
        "version": "DW4CORE 300"
      }
    ]
  }
]

CVSS3

4.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for CVELIST:CVE-2023-33992