CVE-2023-24521

MEDIUM

SAP NetWeaver AS ABAP (BSP Framework) - Code Injection

Title source: llm
STIX 2.1

Description

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0144
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (13)
sap/netweaver_as_abap_business_server_pages 700
sap/netweaver_as_abap_business_server_pages 701
sap/netweaver_as_abap_business_server_pages 702
sap/netweaver_as_abap_business_server_pages 731
sap/netweaver_as_abap_business_server_pages 740
sap/netweaver_as_abap_business_server_pages 750
sap/netweaver_as_abap_business_server_pages 751
sap/netweaver_as_abap_business_server_pages 752
sap/netweaver_as_abap_business_server_pages 753
sap/netweaver_as_abap_business_server_pages 754
... and 3 more
Published Feb 14, 2023
Tracked Since Feb 18, 2026