CVE-2023-32115
SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.2EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Affected products
SAP_SE · Master Data Synchronization (MDS COMPARE TOOL)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →