← Back

CVE-2023-37491

nvd nist
Published: Aug 8, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server. This may lead to unauthorized read and write of data as well as rendering the system unavailable.

Affected (9)

Products: Sap: Message Server
1 product
Message Server
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version kernel_7.22
Version kernel_7.53
Version kernel_7.54
Version kernel_7.77
Version krnl64nuc_7.22
Version krnl64nuc_7.22ex
Version rnl64uc_7.22
Version rnl64uc_7.22ext
Version rnl64uc_7.53

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.