PT-2021-7578 · Sap · Sap Netweaver As Java
Published
2021-01-09
·
Updated
2023-01-13
·
CVE-2023-0017
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS for Java version 7.50
Description
The issue is related to improper access control in SAP NetWeaver AS for Java, allowing an unauthenticated attacker to attach to an open interface and utilize an open naming and directory API. This can lead to unauthorized operations affecting users and data on the current system, potentially granting the attacker full read access to user data, enabling modifications to user data, and making services within the system unavailable.
Recommendations
For SAP NetWeaver AS for Java version 7.50, consider restricting access to the open interface and the open naming and directory API until a patch is available. As a temporary workaround, limit the services that can be accessed through these interfaces to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Java