PT-2023-22156 · Sap · Abap Platform+1

CVE-2023-29108

·

Published

2023-04-11

·

Updated

2023-04-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABAP Platform versions 7.85 through 7.91 SAP Web Dispatcher versions 7.85 through 7.89
Description The IP filter in ABAP Platform and SAP Web Dispatcher may be vulnerable due to erroneous IP netmask handling, potentially enabling access to backend applications from unwanted sources.
Recommendations For ABAP Platform versions 7.85 through 7.91, update to a version that includes a fix for the IP netmask handling issue. For SAP Web Dispatcher versions 7.85 through 7.89, update to a version that includes a fix for the IP netmask handling issue. As a temporary workaround, consider restricting access to backend applications to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29108

Affected Products

Abap Platform
Sap Web Dispatcher