Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)
CVE-2023-27893
8.8HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 March 2023
Summary
An attacker with a non-administrative role in SAP Solution Manager and ABAP managed systems can exploit a vulnerable interface to execute functions beyond their permitted scope. This can lead to unauthorized access, allowing the attacker to read or modify sensitive user or application data, and could potentially disrupt the application's availability. Such vulnerabilities highlight the importance of stringent access controls and regular audits to safeguard critical applications.
Affected Version(s)
Solution Manager and ABAP managed systems 2088_1_700
Solution Manager and ABAP managed systems 2008_1_710
Solution Manager and ABAP managed systems 740
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved