9.8
CVE-2023-0014
- EPSS 0.39%
- Veröffentlicht 10.01.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:23
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version700 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version701 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version702 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version710 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version711 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version730 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version731 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version740 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version750 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version751 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version752 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version753 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version754 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version755 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version756 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version757 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Kernel Version7.22
SAP ≫ Netweaver Application Server Abap Kernel Version7.53
SAP ≫ Netweaver Application Server Abap Kernel Version7.77
SAP ≫ Netweaver Application Server Abap Kernel Version7.81
SAP ≫ Netweaver Application Server Abap Kernel Version7.85
SAP ≫ Netweaver Application Server Abap Kernel Version7.89
SAP ≫ Netweaver Application Server Abap Krnl64nuc Version7.22
SAP ≫ Netweaver Application Server Abap Krnl64nuc Version7.22ext
SAP ≫ Netweaver Application Server Abap Krnl64uc Version7.22
SAP ≫ Netweaver Application Server Abap Krnl64uc Version7.22ext
SAP ≫ Netweaver Application Server Abap Krnl64uc Version7.53
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.39% | 0.591 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
cna@sap.com | 9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).