CVE-2023-39436

MEDIUM

SAP Supplier Relationship Management 600-606, 616-617 - Unauthenticated Information Disclosure

Title source: llm
STIX 2.1

Description

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.

References (2)

Core 2

Scores

CVSS v3 5.8
EPSS 0.0021
EPSS Percentile 43.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (8)
sap/supplier_relationship_management 600
sap/supplier_relationship_management 602
sap/supplier_relationship_management 603
sap/supplier_relationship_management 604
sap/supplier_relationship_management 605
sap/supplier_relationship_management 606
sap/supplier_relationship_management 616
sap/supplier_relationship_management 617
Published Aug 08, 2023
Tracked Since Feb 18, 2026