Information Disclosure in SAP Supplier Relationship Management
CVE-2023-39436
5.8MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 8 August 2023
Summary
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.
Affected Version(s)
SAP Supplier Relationship Management 600
SAP Supplier Relationship Management 602
SAP Supplier Relationship Management 603
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved