PT-2023-31268 · Sap · Sap Solution Manager

Publicado

2023-12-11

·

Atualizado

2023-12-14

·

CVE-2023-49587

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Solution Manager version 720
Description The issue allows an authorized attacker to execute certain deprecated function modules, which can read or modify data of the same or other components without user interaction over the network.
Recommendations For SAP Solution Manager version 720, consider restricting access to deprecated function modules to minimize the risk of exploitation. As a temporary workaround, disabling the execution of these deprecated function modules can help until a more permanent solution is available.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49587

Produtos afetados

Sap Solution Manager