CVE-2023-23853

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 February 2023

Summary

An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.

Affected Version(s)

NetWeaver Application Server for ABAP and ABAP Platform 700

NetWeaver Application Server for ABAP and ABAP Platform 702

NetWeaver Application Server for ABAP and ABAP Platform 731

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.