← Back

CVE-2023-41366

nvd nist
Published: Nov 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.

Affected (15)

1 product
Netweaver Application Server Abap
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version kernel64nuc_7.22
Version kernel64nuc_7.22ext
Version kernel64uc_7.22
Version kernel64uc_7.22ext
Version kernel64uc_7.53
Version kernel_7.22
Version kernel_7.53
Version kernel_7.54
Version kernel_7.77
Version kernel_7.85
Version kernel_7.89
Version kernel_7.91
Version kernel_7.92
Version kernel_7.93
Version kernel_7.94

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.