PT-2023-4111 · Sap · Xs Advanced Runtime+5
Published
2023-07-10
·
Updated
2023-07-18
·
CVE-2023-33987
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SAP Web Dispatcher versions 7.49 through 7.90
KERNEL versions 7.49 through 7.90
KRNL64NUC version 7.49
KRNL64UC versions 7.49 through 7.53
HDB version 2.00
XS ADVANCED RUNTIME version 1.00
SAP EXTENDED APP SERVICES version 1
Description
The issue is related to the handling of HTTP requests in SAP Web Dispatcher. An unauthenticated attacker can submit a maliciously crafted request over a network to a front-end server, which may result in a back-end server confusing the boundaries of malicious and legitimate messages. This can lead to the back-end server executing a malicious payload, allowing the attacker to read or modify information on the server or make it temporarily unavailable.
Recommendations
For SAP Web Dispatcher versions 7.49 through 7.90, update to a version that includes the fix for this issue.
For KERNEL versions 7.49 through 7.90, update to a version that includes the fix for this issue.
For KRNL64NUC version 7.49, update to a version that includes the fix for this issue.
For KRNL64UC versions 7.49 through 7.53, update to a version that includes the fix for this issue.
For HDB version 2.00, update to a version that includes the fix for this issue.
For XS ADVANCED RUNTIME version 1.00, update to a version that includes the fix for this issue.
For SAP EXTENDED APP SERVICES version 1, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SAP Web Dispatcher to minimize the risk of exploitation.
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hdb
Kernel
Krnl64Uc
Sap Web Dispatcher
Sap Extended App Services
Xs Advanced Runtime