PT-2023-4048 · Sap · Xs Advanced Runtime+5

Published

2023-07-11

·

Updated

2023-09-09

·

CVE-2023-35871

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Web Dispatcher versions WEBDISP 7.53 through WEBDISP 7.93 KERNEL versions 7.53 through 7.93 KRNL64UC version 7.53 HDB version 2.00 XS ADVANCED RUNTIME version 1.00 SAP EXTENDED APP SERVICES version 1
Description The vulnerability is related to logical errors in memory management, which can be exploited by an unauthenticated attacker to cause memory corruption. This may lead to information disclosure or system crashes, having a low impact on confidentiality and a high impact on the integrity and availability of the system.
Recommendations For SAP Web Dispatcher versions WEBDISP 7.53 through WEBDISP 7.93, update to a version that includes the fix for the memory management issue. For KERNEL versions 7.53 through 7.93, update to a version that includes the fix for the memory management issue. For KRNL64UC version 7.53, update to a version that includes the fix for the memory management issue. For HDB version 2.00, update to a version that includes the fix for the memory management issue. For XS ADVANCED RUNTIME version 1.00, update to a version that includes the fix for the memory management issue. For SAP EXTENDED APP SERVICES version 1, update to a version that includes the fix for the memory management issue. As a temporary workaround, consider restricting access to the SAP Web Dispatcher to minimize the risk of exploitation.

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-04346
CVE-2023-35871

Affected Products

Hdb
Kernel
Krnl64Uc
Sap Web Dispatcher
Sap Extended App Services
Xs Advanced Runtime