PT-2023-7893 · Sap · Sap Btp Security Services Integration Library+2
Published
2023-12-11
·
Updated
2024-09-28
·
CVE-2023-49583
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
SAP BTP Security Services Integration Library (@sap/xssec) versions < 3.6.0
Description
The issue is related to insecure privilege management in the SAP XS Advanced sap/xssec library, which is part of the SAP Business Technology Platform (BTP). This allows an unauthenticated attacker to escalate privileges under certain conditions, obtaining arbitrary permissions within the application.
Recommendations
For versions < 3.6.0, update to version 3.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.
Fix
Improper Privilege Management
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Btp Security Services Integration Library
Sap Business Technology Platform
Sap Xs Advanced