PT-2023-22156 · Sap · Abap Platform+1
Published
2023-04-11
·
Updated
2023-04-18
·
CVE-2023-29108
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABAP Platform versions 7.85 through 7.91
SAP Web Dispatcher versions 7.85 through 7.89
Description
The IP filter in ABAP Platform and SAP Web Dispatcher may be vulnerable due to erroneous IP netmask handling, potentially enabling access to backend applications from unwanted sources.
Recommendations
For ABAP Platform versions 7.85 through 7.91, update to a version that includes a fix for the IP netmask handling issue.
For SAP Web Dispatcher versions 7.85 through 7.89, update to a version that includes a fix for the IP netmask handling issue.
As a temporary workaround, consider restricting access to backend applications to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Web Dispatcher