CVE-2023-25615
SQL Injection vulnerability in SAP ABAP Platform
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.8EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
14 mar 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database queries over the network and gain access to the unintended data. This may lead to a high impact on the confidentiality and no impact on the availability and integrity of the application.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Productos afectados
SAP · ABAP Platform¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →