CVE-2023-27268

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:netweaver_application_server_for_java:7.50:*:*:*:*:*:*:*

History

21 Nov 2024, 07:52

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3288480 - Permissions Required () https://launchpad.support.sap.com/#/notes/3288480 - Permissions Required
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

11 Apr 2023, 04:16

Type Values Removed Values Added
Summary SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges. SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.

Information

Published : 2023-03-14 05:15

Updated : 2024-11-21 07:52


NVD link : CVE-2023-27268

Mitre link : CVE-2023-27268

CVE.ORG link : CVE-2023-27268


JSON object : View

Products Affected

sap

  • netweaver_application_server_for_java
CWE
CWE-284

Improper Access Control