PT-2023-20652 · Sap · Sap Netweaver As Abap+1

CVE-2023-26459

·

Publicado

2023-03-14

·

Atualizado

2023-04-11

CVSS v3.1

7.4

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791
Description The issue is caused by improper input controls, allowing an authenticated non-administrative user to craft a request that triggers the application server to send a request to an arbitrary URL. This can lead to the revelation, modification, or unavailability of non-sensitive information, resulting in a low impact on confidentiality, integrity, and availability.
Recommendations For SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, consider implementing proper input controls to prevent malicious requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26459

Produtos afetados

Abap Platform
Sap Netweaver As Abap