PT-2023-4246 · Sap · Sap Message Server

Published

2023-06-07

·

Updated

2024-09-28

·

CVE-2023-37491

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Message Server versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT
Description The issue is related to the Access Control List (ACL) of the SAP Message Server, which can be bypassed under certain conditions. This may allow an authenticated malicious user to gain unauthorized access to the network of SAP systems served by the attacked SAP Message Server, potentially leading to unauthorized read and write of data, as well as rendering the system unavailable.
Recommendations For SAP Message Server versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, consider restricting access to the ACL to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the vulnerable ACL functionality until a patch is available. Restrict access to the SAP Message Server to minimize the risk of exploitation.

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-04561
CVE-2023-37491

Affected Products

Sap Message Server