PT-2023-4095 · Sap · Abap Platform+1

Published

2023-07-10

·

Updated

2024-09-28

·

CVE-2023-35874

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP and ABAP Platform versions 7.22 through 7.93
Description The issue is related to improper authentication checks for functionalities that require user identity. This can allow an attacker to perform malicious actions over the network, potentially causing a limited impact on confidentiality, integrity, and availability.
Recommendations For SAP NetWeaver Application Server ABAP and ABAP Platform versions 7.22 through 7.93, consider implementing additional authentication measures to mitigate the risk of exploitation. As a temporary workaround, restrict access to functionalities that require user identity until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-04398
CVE-2023-35874

Affected Products

Abap Platform
Sap Netweaver Application Server Abap