PT-2023-7890 · Sap · Sap Btp Security Services Integration Library

·

CVE-2023-50422

·

Publicado

2023-12-11

·

Atualizado

2024-09-28

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP BTP Security Services Integration Library versions below 2.17.0 SAP BTP Security Services Integration Library versions from 3.0.0 to before 3.3.0
Description The issue is related to insecure privilege management in the SAP BTP Security Services Integration Library, allowing an unauthenticated attacker to obtain arbitrary permissions within the application under certain conditions. On successful exploitation, this can lead to an escalation of privileges.
Recommendations For versions below 2.17.0, upgrade to version 2.17.0 or later. For versions from 3.0.0 to before 3.3.0, upgrade to version 3.3.0 or later. It is recommended to upgrade to the latest released version to ensure all security patches are applied.

Exploit

Correção

IDOR

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08961
CVE-2023-50422
GHSA-59C9-PXQ8-9C73
GHSA-92CG-GHQ6-9587
GHSA-GCGW-Q47M-PRVJ
GHSA-M8RW-RCPQ-2VP2
GO-2023-2400

Produtos afetados

Sap Btp Security Services Integration Library