PT-2021-7578 · Sap · Sap Netweaver As Java

Published

2021-01-09

·

Updated

2023-01-13

·

CVE-2023-0017

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS for Java version 7.50
Description The issue is related to improper access control in SAP NetWeaver AS for Java, allowing an unauthenticated attacker to attach to an open interface and utilize an open naming and directory API. This can lead to unauthorized operations affecting users and data on the current system, potentially granting the attacker full read access to user data, enabling modifications to user data, and making services within the system unavailable.
Recommendations For SAP NetWeaver AS for Java version 7.50, consider restricting access to the open interface and the open naming and directory API until a patch is available. As a temporary workaround, limit the services that can be accessed through these interfaces to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-00120
CVE-2023-0017

Affected Products

Sap Netweaver As Java