PT-2023-7890 · Sap · Sap Btp Security Services Integration Library
Rosenblueh
·
Publicado
2023-12-11
·
Atualizado
2024-09-28
·
CVE-2023-50422
CVSS v2.0
9.4
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
SAP BTP Security Services Integration Library versions below 2.17.0
SAP BTP Security Services Integration Library versions from 3.0.0 to before 3.3.0
Description
The issue is related to insecure privilege management in the SAP BTP Security Services Integration Library, allowing an unauthenticated attacker to obtain arbitrary permissions within the application under certain conditions. On successful exploitation, this can lead to an escalation of privileges.
Recommendations
For versions below 2.17.0, upgrade to version 2.17.0 or later.
For versions from 3.0.0 to before 3.3.0, upgrade to version 3.3.0 or later.
It is recommended to upgrade to the latest released version to ensure all security patches are applied.
Correção
IDOR
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Btp Security Services Integration Library