Lucene search

K
githubGitHub Advisory DatabaseGHSA-GCGW-Q47M-PRVJ
HistoryDec 12, 2023 - 3:31 a.m.

Improper JWT Signature Validation in SAP Security Services Library

2023-12-1203:31:45
CWE-269
CWE-639
GitHub Advisory Database
github.com
5
sap
jwt
signature validation
security services
privilege escalation

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.3%

SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

Affected configurations

Vulners
Node
com.sap.cloud.securityspring-securityRange3.0.03.3.0
OR
com.sap.cloud.securityspring-securityRange<2.17.0
OR
com.sap.cloud.security.xsuaaspring-xsuaaRange3.0.03.3.0
OR
com.sap.cloud.security.xsuaaspring-xsuaaRange<2.17.0
OR
com.sap.cloud.securityjava-securityRange3.0.03.3.0
OR
com.sap.cloud.securityjava-securityRange<2.17.0
VendorProductVersionCPE
com.sap.cloud.securityspring-security*cpe:2.3:a:com.sap.cloud.security:spring-security:*:*:*:*:*:*:*:*
com.sap.cloud.security.xsuaaspring-xsuaa*cpe:2.3:a:com.sap.cloud.security.xsuaa:spring-xsuaa:*:*:*:*:*:*:*:*
com.sap.cloud.securityjava-security*cpe:2.3:a:com.sap.cloud.security:java-security:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for GHSA-GCGW-Q47M-PRVJ