PT-2023-4095 · Sap · Abap Platform+1

CVE-2023-35874

·

Published

2023-07-10

·

Updated

2024-09-28

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP and ABAP Platform versions 7.22 through 7.93
Description The issue is related to improper authentication checks for functionalities that require user identity. This can allow an attacker to perform malicious actions over the network, potentially causing a limited impact on confidentiality, integrity, and availability.
Recommendations For SAP NetWeaver Application Server ABAP and ABAP Platform versions 7.22 through 7.93, consider implementing additional authentication measures to mitigate the risk of exploitation. As a temporary workaround, restrict access to functionalities that require user identity until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04398
CVE-2023-35874

Affected Products

Abap Platform
Sap Netweaver Application Server Abap