CRITICAL🇵🇱 Wersja polska

CVE-2023-0014

CVSS 9.0v3.1pub. 2023-01-10upd. 2024-11-21

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Sap Netweaver Application Server Abap

    APP
    Sap
    700701702710711730731740750751752753754755756+ 1 more
  • Sap Netweaver Application Server Abap Kernel

    APP
    Sap
    7.227.537.777.817.857.89
  • Sap Netweaver Application Server Abap Krnl64nuc

    APP
    Sap
    7.227.22ext
  • Sap Netweaver Application Server Abap Krnl64uc

    APP
    Sap
    7.227.22ext7.53
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-22536CRITICAL10.0⚠ KEVPL ✓same product

Request Smuggling w SAP NetWeaver i SAP Web Dispatcher — CVSS 10.0

CVE-2026-0488CRITICAL9.9PL ✓same product

SAP CRM / S/4HANA Scripting Editor — nieautoryzowane wykonanie SQL

CVE-2023-40309CRITICAL9.8PL ✓same product

SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation

CVE-2023-27269CRITICAL9.6PL ✓same product

SAP NetWeaver AS ABAP — path traversal umożliwia nadpisanie plików systemowych

CVE-2023-27500CRITICAL9.6PL ✓same product

SAP NetWeaver AS ABAP: path traversal w SAPRSBRO umożliwia nadpisanie plików systemowych