PT-2023-21404 · Sap · Sap Crm
Published
2023-04-11
·
Updated
2023-04-14
·
CVE-2023-27897
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP CRM versions 700 through 713
Description
The issue allows an authenticated attacker with a non-administrative role and common remote execution authorization to use a vulnerable interface and execute an application function, performing actions they would not normally be permitted to do. Depending on the function executed, this can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
Recommendations
For SAP CRM versions 700 through 713, consider restricting access to the vulnerable interface until a patch is available. As a temporary workaround, limit the execution of application functions to only those necessary for operational tasks, and monitor for any unauthorized access or changes.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Crm