PT-2023-3748 · Sap · Sap Netweaver
Published
2023-06-13
·
Updated
2024-09-28
·
CVE-2023-32114
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver (Change and Transport System) versions 702 through 757
Description
The issue is related to a lack of resource control mechanism in the Change and Transport System component of SAP NetWeaver. This allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly, potentially slowing down or making the server unavailable. The impact is limited to Availability, with no effect on Confidentiality and Integrity of the application. Exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations
For versions 702 through 757, consider restricting access to the benchmark program to prevent malicious use, and limit the privileges of authenticated users to minimize the risk of exploitation. As a temporary workaround, consider disabling the benchmark program until a more permanent solution is available.
Fix
Incorrect Permission
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Netweaver