CVE-2023-49581
SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.1EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
12 dic 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Productos afectados
SAP_SE · SAP NetWeaver Application Server ABAP and ABAP Platform¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →