SAP Vulnerabilities and Affected Products
Vulnerabilities associated with NetWeaver AS for Java.
Products
Clear product- NetWeaver19 vulnerabilities
- NetWeaver AS for ABAP and ABAP Platform7 vulnerabilities
- SAP BusinessObjects Business Intelligence Platform5 vulnerabilities
- SAP Fiori Client5 vulnerabilities
- commerce_cloud4 vulnerabilities
- Solution Manager4 vulnerabilities
- BusinessObjects Business Intelligence Platform (Web Services)3 vulnerabilities
- NetWeaver Application Server for ABAP and ABAP Platform3 vulnerabilities
- NetWeaver AS ABAP (BSP Framework)3 vulnerabilities
- NetWeaver AS for Java3 vulnerabilities
- SAP BusinessObjects Business Intelligence3 vulnerabilities
- SAP HANA extended application services3 vulnerabilities
- SAP Internet Graphics Server (IGS)3 vulnerabilities
- Application Interface Framework (Message Dashboard)2 vulnerabilities
- Business Planning and Consolidation2 vulnerabilities
- business_objects_business_intelligence_platform2 vulnerabilities
- commerce_hycom2 vulnerabilities
- CRM (WebClient UI)2 vulnerabilities
- NetWeaver Process Integration2 vulnerabilities
- netweaver_application_server_java2 vulnerabilities
- SAP Adaptive Server Enterprise (ASE)2 vulnerabilities
- SAP BusinessObjects Business Intelligence Suite2 vulnerabilities
- SAP Enterprise Financial Services2 vulnerabilities
- SAP HANA2 vulnerabilities
- SAP NetWeaver AS Java (ServerCore)2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-26460MEDIUM | Improper Access Control in SAP NetWeaver AS Java (Cache Management Service)Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity CWE-284Mar 14, 2023 | CVSS5.3v3.1 | EPSS0.476% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-23857CRITICAL | Improper Access Control in SAP NetWeaver AS for JavaDue to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a successful exploitation, the attacker can read and modify some sensitive information but can also be used to lock up any element or operation of the system making that it unresponsive … CWE-287Mar 14, 2023 | CVSS9.9v3.1 | EPSS0.544% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0017CRITICAL | Improper access control in SAP NetWeaver AS for JavaAn unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable. CWE-284Jan 10, 2023 | CVSS9.4v3.1 | EPSS15.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |