SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-3112 SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Github GHSA Github GHSA GHSA-59c9-pxq8-9c73 Improper JWT Signature Validation in SAP Security Services Library
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 28 Sep 2024 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Sat, 28 Sep 2024 22:30:00 +0000

Type Values Removed Values Added
Description SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application. SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Weaknesses CWE-749

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-09-28T22:17:43.519Z

Reserved: 2023-12-09T17:19:02.677Z

Link: CVE-2023-50422

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-12T02:15:08.587

Modified: 2024-11-21T08:36:57.380

Link: CVE-2023-50422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.