PT-2023-7893 · Sap · Sap Btp Security Services Integration Library+2

Published

2023-12-11

·

Updated

2024-09-28

·

CVE-2023-49583

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP BTP Security Services Integration Library (@sap/xssec) versions < 3.6.0
Description The issue is related to insecure privilege management in the SAP XS Advanced sap/xssec library, which is part of the SAP Business Technology Platform (BTP). This allows an unauthenticated attacker to escalate privileges under certain conditions, obtaining arbitrary permissions within the application.
Recommendations For versions < 3.6.0, update to version 3.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Improper Privilege Management

IDOR

Weakness Enumeration

Related Identifiers

BDU:2023-08964
CVE-2023-49583
GHSA-P2VX-QJ66-88Q3

Affected Products

Sap Btp Security Services Integration Library
Sap Business Technology Platform
Sap Xs Advanced