CVE-2023-24521
MEDIUMSAP NetWeaver AS ABAP (BSP Framework) - Code Injection
Title source: llmDescription
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://launchpad.support.sap.com/#/notes/3269151
Scores
CVSS v3
6.1
EPSS
0.0144
EPSS Percentile
80.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (13)
sap/netweaver_as_abap_business_server_pages
700
sap/netweaver_as_abap_business_server_pages
701
sap/netweaver_as_abap_business_server_pages
702
sap/netweaver_as_abap_business_server_pages
731
sap/netweaver_as_abap_business_server_pages
740
sap/netweaver_as_abap_business_server_pages
750
sap/netweaver_as_abap_business_server_pages
751
sap/netweaver_as_abap_business_server_pages
752
sap/netweaver_as_abap_business_server_pages
753
sap/netweaver_as_abap_business_server_pages
754
... and 3 more
Published
Feb 14, 2023
Tracked Since
Feb 18, 2026