CVE-2023-29185

MEDIUM

SAP NetWeaver AS ABAP Business Server Pages - Authenticated Denial of Service via Resource Consumption

Title source: llm
STIX 2.1

Description

SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

Scores

CVSS v3 5.3
EPSS 0.0047
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (13)
sap/netweaver_as_abap_business_server_pages 700
sap/netweaver_as_abap_business_server_pages 701
sap/netweaver_as_abap_business_server_pages 702
sap/netweaver_as_abap_business_server_pages 731
sap/netweaver_as_abap_business_server_pages 740
sap/netweaver_as_abap_business_server_pages 750
sap/netweaver_as_abap_business_server_pages 751
sap/netweaver_as_abap_business_server_pages 752
sap/netweaver_as_abap_business_server_pages 753
sap/netweaver_as_abap_business_server_pages 754
... and 3 more
Published Apr 11, 2023
Tracked Since Feb 18, 2026