9.8
CVE-2023-0014
- EPSS 0.69%
- Veröffentlicht 10.01.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:23
- Erkennungen
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version 700 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 701 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 702 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 710 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 711 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 730 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 731 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 740 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 750 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 751 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 752 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 753 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 754 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 755 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 756 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Version 757 SwEdition sap_basis
SAP ≫ Netweaver Application Server Abap Kernel Version 7.22
SAP ≫ Netweaver Application Server Abap Kernel Version 7.53
SAP ≫ Netweaver Application Server Abap Kernel Version 7.77
SAP ≫ Netweaver Application Server Abap Kernel Version 7.81
SAP ≫ Netweaver Application Server Abap Kernel Version 7.85
SAP ≫ Netweaver Application Server Abap Kernel Version 7.89
SAP ≫ Netweaver Application Server Abap Krnl64nuc Version 7.22
SAP ≫ Netweaver Application Server Abap Krnl64nuc Version 7.22ext
SAP ≫ Netweaver Application Server Abap Krnl64uc Version 7.22
SAP ≫ Netweaver Application Server Abap Krnl64uc Version 7.22ext
SAP ≫ Netweaver Application Server Abap Krnl64uc Version 7.53
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.69% | 0.48 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| SAP | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
https://launchpad.support.sap.com/#/notes/3089413