HTTP Verb Tampering vulnerability in SAP CRM (WebClient UI)
CVE-2023-29189

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 April 2023

Summary

SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields

Affected Version(s)

CRM (WebClient UI) S4FND 102

CRM (WebClient UI) S4FND 103

CRM (WebClient UI) S4FND 104

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.