PT-2023-7891 · Sap · Sap-Xssec+1
Rosenblueh
·
Publicado
2023-12-11
·
Atualizado
2024-09-28
·
CVE-2023-50423
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP BTP Security Services Integration Library (Python sap-xssec) versions < 4.1.0
Description
The issue is related to insecure privilege management in the SAP XS Advanced sap-xssec library, which is part of the SAP Business Technology Platform (BTP). This allows an unauthenticated attacker to escalate privileges under certain conditions, obtaining arbitrary permissions within the application.
Recommendations
Upgrade to a patched version >= 4.1.0
It is recommended to upgrade to the latest released version to ensure the issue is fully resolved.
No workarounds are available for this issue.
Correção
IDOR
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Btp Security Services Integration Library
Sap-Xssec