Escalation of Privileges in SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library)
CVE-2023-50422

9.8CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 December 2023

Summary

The SAP BTP Security Services Integration Library, particularly in versions prior to 2.17.0 and between 3.0.0 and 3.2.9, is susceptible to a privilege escalation issue. This vulnerability enables an unauthenticated attacker to exploit certain conditions within the library, potentially allowing them to gain unauthorized permissions and access. Organizations using affected versions should prioritize their upgrade to mitigate the risk of exploitation.

Affected Version(s)

cloud-security-services-integration-library < 2.17.0 < 2.17.0

cloud-security-services-integration-library 3.0.0 < 3.3.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.