PT-2023-7891 · Sap · Sap-Xssec+1

Rosenblueh

·

Publicado

2023-12-11

·

Atualizado

2024-09-28

·

CVE-2023-50423

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP BTP Security Services Integration Library (Python sap-xssec) versions < 4.1.0
Description The issue is related to insecure privilege management in the SAP XS Advanced sap-xssec library, which is part of the SAP Business Technology Platform (BTP). This allows an unauthenticated attacker to escalate privileges under certain conditions, obtaining arbitrary permissions within the application.
Recommendations Upgrade to a patched version >= 4.1.0 It is recommended to upgrade to the latest released version to ensure the issue is fully resolved. No workarounds are available for this issue.

Correção

IDOR

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08962
CVE-2023-50423
GHSA-6MJG-37CP-42X5
GHSA-P99H-PFG6-QRFG
PYSEC-2023-261

Produtos afetados

Sap Btp Security Services Integration Library
Sap-Xssec