Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)
CVE-2023-50422
9.8CRITICAL
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 December 2023
Summary
The SAP BTP Security Services Integration Library, particularly in versions prior to 2.17.0 and between 3.0.0 and 3.2.9, is susceptible to a privilege escalation issue. This vulnerability enables an unauthenticated attacker to exploit certain conditions within the library, potentially allowing them to gain unauthorized permissions and access. Organizations using affected versions should prioritize their upgrade to mitigate the risk of exploitation.
Affected Version(s)
cloud-security-services-integration-library < 2.17.0 < 2.17.0
cloud-security-services-integration-library 3.0.0 < 3.3.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved