CVE-2023-41366
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
Bajo ciertas condiciones SAP NetWeaver Application Server ABAP - versiones KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, permite que un atacante no autenticado acceda a datos no deseados debido a la falta de restricciones aplicadas, lo que puede generar un bajo impacto en la confidencialidad y ningún impacto en la integridad y disponibilidad de la aplicación.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-08-29 CVE Reserved
- 2023-11-14 CVE Published
- 2024-09-03 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2023-11-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.22 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.22" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.53 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.53" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.54 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.54" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.77 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.77" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.85 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.85" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.89 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.89" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.91 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.91" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.92 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.92" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.93 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.93" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel_7.94 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel_7.94" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel64nuc_7.22 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel64nuc_7.22" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel64nuc_7.22ext Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel64nuc_7.22ext" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel64uc_7.22 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel64uc_7.22" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel64uc_7.22ext Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel64uc_7.22ext" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Application Server Abap Search vendor "Sap" for product "Netweaver Application Server Abap" | kernel64uc_7.53 Search vendor "Sap" for product "Netweaver Application Server Abap" and version "kernel64uc_7.53" | - |
Affected
|