CVE-2023-49581

S

AP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:sap_basis:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:sap_basis:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:sap_basis:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:sap_basis:*:*:*

History

21 Nov 2024, 08:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.4
v2 : unknown
v3 : 4.1
References () https://me.sap.com/notes/3392547 - Permissions Required, Vendor Advisory () https://me.sap.com/notes/3392547 - Permissions Required, Vendor Advisory
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

Information

Published : 2023-12-12 02:15

Updated : 2024-11-21 08:33


NVD link : CVE-2023-49581

Mitre link : CVE-2023-49581

CVE.ORG link : CVE-2023-49581


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')