PT-2023-19669 · Sap · Sap Netweaver As Abap

CVE-2023-24521

·

Publicado

2023-02-14

·

Atualizado

2023-04-12

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP (BSP Framework) versions 700 through 757
Description The issue is caused by insufficient input sanitization, allowing an unauthenticated user to alter the current session of the user by injecting malicious code over the network. This may lead to a limited impact on the confidentiality and integrity of the application.
Recommendations For SAP NetWeaver AS ABAP (BSP Framework) versions 700 through 757, update to a version that includes the necessary input sanitization fixes to prevent session alteration and unauthorized data access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24521

Produtos afetados

Sap Netweaver As Abap