PT-2023-4071 · Sap · Sap Netweaver Process Integration

Published

2023-07-11

·

Updated

2023-07-19

·

CVE-2023-35872

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Process Integration version SAP XIAF 7.50
Description The issue is related to the Message Display Tool (MDT) component of SAP NetWeaver Process Integration, which lacks proper authentication checks for certain functionalities. This allows an unauthenticated user to access technical data about the product status and its configuration, potentially causing limited impact on confidentiality and availability of the application. However, it does not allow access to sensitive information or administrative functionalities.
Recommendations For SAP NetWeaver Process Integration version SAP XIAF 7.50, consider implementing additional authentication checks for the Message Display Tool (MDT) component to prevent unauthorized access to technical data. As a temporary workaround, restrict access to the MDT component to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04369
CVE-2023-35872

Affected Products

Sap Netweaver Process Integration