Description
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.
Published: 2023-01-10
Score: 9.4 Critical
EPSS: 4.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-12122 An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.
History

Wed, 09 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Sap Netweaver Application Server For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-04-09T13:54:09.602Z

Reserved: 2022-12-20T03:49:32.991Z

Link: CVE-2023-0017

cve-icon Vulnrichment

Updated: 2024-08-02T04:54:32.802Z

cve-icon NVD

Status : Modified

Published: 2023-01-10T04:15:09.887

Modified: 2024-11-21T07:36:24.103

Link: CVE-2023-0017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses