PT-2023-4071 · Sap · Sap Netweaver Process Integration
CVE-2023-35872
·
Publicado
2023-07-11
·
Atualizado
2023-07-19
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Process Integration version SAP XIAF 7.50
Description
The issue is related to the Message Display Tool (MDT) component of SAP NetWeaver Process Integration, which lacks proper authentication checks for certain functionalities. This allows an unauthenticated user to access technical data about the product status and its configuration, potentially causing limited impact on confidentiality and availability of the application. However, it does not allow access to sensitive information or administrative functionalities.
Recommendations
For SAP NetWeaver Process Integration version SAP XIAF 7.50, consider implementing additional authentication checks for the Message Display Tool (MDT) component to prevent unauthorized access to technical data. As a temporary workaround, restrict access to the MDT component to minimize the risk of exploitation.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver Process Integration