5.3
CVE-2023-41366
- EPSS 0.22%
- Published 14.11.2023 01:15:07
- Last modified 21.11.2024 08:21:10
- Source cna@sap.com
- Teams watchlist Login
- Open Login
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Versionkernel_7.22
SAP ≫ Netweaver Application Server Abap Versionkernel_7.53
SAP ≫ Netweaver Application Server Abap Versionkernel_7.54
SAP ≫ Netweaver Application Server Abap Versionkernel_7.77
SAP ≫ Netweaver Application Server Abap Versionkernel_7.85
SAP ≫ Netweaver Application Server Abap Versionkernel_7.89
SAP ≫ Netweaver Application Server Abap Versionkernel_7.91
SAP ≫ Netweaver Application Server Abap Versionkernel_7.92
SAP ≫ Netweaver Application Server Abap Versionkernel_7.93
SAP ≫ Netweaver Application Server Abap Versionkernel_7.94
SAP ≫ Netweaver Application Server Abap Versionkernel64nuc_7.22
SAP ≫ Netweaver Application Server Abap Versionkernel64nuc_7.22ext
SAP ≫ Netweaver Application Server Abap Versionkernel64uc_7.22
SAP ≫ Netweaver Application Server Abap Versionkernel64uc_7.22ext
SAP ≫ Netweaver Application Server Abap Versionkernel64uc_7.53
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.447 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
cna@sap.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.