PT-2023-1064 · Sap · Sap Netweaver Abap Server+1
CVE-2023-0014
·
Publicado
2023-01-09
·
Atualizado
2023-07-01
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver ABAP Server and ABAP Platform versions SAP BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT
Description
The issue is related to the bypass of the authentication procedure in the SAP NetWeaver Application Server ABAP. This could allow a remote attacker to gain unauthorized access to the system. The problem creates information about system identity in an ambiguous format, leading to a potential capture-replay vulnerability that malicious users could exploit to obtain illegitimate access to the system.
Recommendations
For SAP NetWeaver ABAP Server and ABAP Platform versions SAP BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, consider applying the recommended security patches or updates from SAP to fix the authentication bypass issue.
As a temporary workaround, restrict access to sensitive system functions and monitor system activity closely to minimize the risk of exploitation.
Avoid using ambiguous system identity formats until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver Abap Server
Sap Netweaver Application Server Abap