CVE-2023-33987

HIGH

SAP Web Dispatcher <7.90 - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.

Scores

CVSS v3 8.6
EPSS 0.0018
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-444
Status published
Products (24)
sap/web_dispatcher 7.49
sap/web_dispatcher 7.53
sap/web_dispatcher 7.54
sap/web_dispatcher 7.77
sap/web_dispatcher 7.81
sap/web_dispatcher 7.85
sap/web_dispatcher 7.88
sap/web_dispatcher 7.89
sap/web_dispatcher 7.90
sap/web_dispatcher hdb_2.00
... and 14 more
Published Jul 11, 2023
Tracked Since Feb 18, 2026