PT-2023-20652 · Sap · Sap Netweaver As Abap+1
CVE-2023-26459
·
Published
2023-03-14
·
Updated
2023-04-11
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791
Description
The issue is caused by improper input controls, allowing an authenticated non-administrative user to craft a request that triggers the application server to send a request to an arbitrary URL. This can lead to the revelation, modification, or unavailability of non-sensitive information, resulting in a low impact on confidentiality, integrity, and availability.
Recommendations
For SAP NetWeaver AS for ABAP and ABAP Platform versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, consider implementing proper input controls to prevent malicious requests.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Netweaver As Abap