CVE-2023-23851
CVE-2023-23851
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
14 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Productos afectados
SAP · Business Planning and Consolidation¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →