CVE-2023-24521
Summary
| CVE | CVE-2023-24521 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-14 04:15:00 UTC |
| Updated | 2023-04-11 22:15:00 UTC |
| Description | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver As Abap Business Server Pages | 700 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 701 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 702 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 731 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 740 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 750 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 751 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 752 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 753 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 754 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 755 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 756 | All | All | All |
| Application | Sap | Netweaver As Abap Business Server Pages | 757 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| Access Denied | MISC | www.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.