In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2023-04-11T02:50:00.642Z

Updated: 2024-08-02T12:23:30.151Z

Reserved: 2023-03-07T07:53:14.887Z

Link: CVE-2023-27897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-11T03:15:07.613

Modified: 2023-04-14T19:47:31.197

Link: CVE-2023-27897

cve-icon Redhat

No data.