Information Disclosure in SAP Supplier Relationship Management
CVE-2023-39436

5.8MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 August 2023

Summary

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.

Affected Version(s)

SAP Supplier Relationship Management 600

SAP Supplier Relationship Management 602

SAP Supplier Relationship Management 603

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.