PT-2023-20652 · Sap · Sap Netweaver As Abap+1
CVE-2023-26459
·
Publicado
2023-03-14
·
Atualizado
2023-04-11
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791
Description
The issue is caused by improper input controls, allowing an authenticated non-administrative user to craft a request that triggers the application server to send a request to an arbitrary URL. This can lead to the revelation, modification, or unavailability of non-sensitive information, resulting in a low impact on confidentiality, integrity, and availability.
Recommendations
For SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, consider implementing proper input controls to prevent malicious requests.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abap Platform
Sap Netweaver As Abap