Description
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

Published: 2023-04-11
Score: 6 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-31631 In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
History

Fri, 07 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Sap Customer Relationship Management
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-02-07T16:54:50.000Z

Reserved: 2023-03-07T07:53:14.887Z

Link: CVE-2023-27897

cve-icon Vulnrichment

Updated: 2024-08-02T12:23:30.151Z

cve-icon NVD

Status : Modified

Published: 2023-04-11T03:15:07.613

Modified: 2024-11-21T07:53:39.440

Link: CVE-2023-27897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses