CVE-2023-0019

MEDIUM

SAP GRC - Confidential Data Exposure

Title source: llm
STIX 2.1

Description

In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (5)
sap/grc_process_control v1100_700
sap/grc_process_control v1100_731
sap/grc_process_control v1200
sap/grc_process_control v1200_750
sap/grc_process_control v8100
Published Feb 14, 2023
Tracked Since Feb 18, 2026