ZeroHour

CVE-2023-0014

CVSS 3.1
9.8 critical
EPSS
<1%p51
Published
()
Modified
Description

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

Vendors
sap
Products
netweaver application server abap, netweaver application server abap kernel, netweaver application server abap krnl64nuc, netweaver application server abap krnl64uc
Weakness
CWE-294
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.