CVE-2023-27893
HIGHSAP Solution Manager - Authenticated Remote Code Execution via Vulnerable Interface
Title source: llmDescription
An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3296476
Scores
CVSS v3
8.8
EPSS
0.0513
EPSS Percentile
90.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
sap/solution_manager
740
Published
Mar 14, 2023
Tracked Since
Feb 18, 2026