Description
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.

Published: 2023-03-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-30281 SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Sap Netweaver Enterprise Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-02-27T15:08:31.768Z

Reserved: 2023-02-22T21:38:25.764Z

Link: CVE-2023-26461

cve-icon Vulnrichment

Updated: 2024-08-02T11:53:52.901Z

cve-icon NVD

Status : Modified

Published: 2023-03-14T05:15:30.333

Modified: 2024-11-21T07:51:32.480

Link: CVE-2023-26461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses