PT-2023-4111 · Sap · Xs Advanced Runtime+5

Published

2023-07-10

·

Updated

2023-07-18

·

CVE-2023-33987

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions SAP Web Dispatcher versions 7.49 through 7.90 KERNEL versions 7.49 through 7.90 KRNL64NUC version 7.49 KRNL64UC versions 7.49 through 7.53 HDB version 2.00 XS ADVANCED RUNTIME version 1.00 SAP EXTENDED APP SERVICES version 1
Description The issue is related to the handling of HTTP requests in SAP Web Dispatcher. An unauthenticated attacker can submit a maliciously crafted request over a network to a front-end server, which may result in a back-end server confusing the boundaries of malicious and legitimate messages. This can lead to the back-end server executing a malicious payload, allowing the attacker to read or modify information on the server or make it temporarily unavailable.
Recommendations For SAP Web Dispatcher versions 7.49 through 7.90, update to a version that includes the fix for this issue. For KERNEL versions 7.49 through 7.90, update to a version that includes the fix for this issue. For KRNL64NUC version 7.49, update to a version that includes the fix for this issue. For KRNL64UC versions 7.49 through 7.53, update to a version that includes the fix for this issue. For HDB version 2.00, update to a version that includes the fix for this issue. For XS ADVANCED RUNTIME version 1.00, update to a version that includes the fix for this issue. For SAP EXTENDED APP SERVICES version 1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SAP Web Dispatcher to minimize the risk of exploitation.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04420
CVE-2023-33987

Affected Products

Hdb
Kernel
Krnl64Uc
Sap Web Dispatcher
Sap Extended App Services
Xs Advanced Runtime