← back
CVE-2023-39436

Information Disclosure in SAP Supplier Relationship Management

CVSS 5.8 MEDIUMEPSS 0.4%CWE-306
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.8EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →