Lucene search

K
cvelistSapCVELIST:CVE-2023-50422
HistoryDec 12, 2023 - 1:31 a.m.

CVE-2023-50422 Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)

2023-12-1201:31:17
CWE-749
sap
www.cve.org
4
cve-2023-50422
privilege escalation
sap btp
security services integration library
java
cloud security services integration library
vulnerability
unauthenticated attacker

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

41.3%

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "cloud-security-services-integration-library",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 2.17.0"
      },
      {
        "lessThan": "3.3.0",
        "status": "affected",
        "version": "3.0.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for CVELIST:CVE-2023-50422