CVE-2023-27268

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:netweaver_application_server_for_java:7.50:*:*:*:*:*:*:*

History

11 Apr 2023, 04:16

Type Values Removed Values Added
Summary SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges. SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.

21 Mar 2023, 17:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Sap
Sap netweaver Application Server For Java
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3288480 - (MISC) https://launchpad.support.sap.com/#/notes/3288480 - Permissions Required
CPE cpe:2.3:a:sap:netweaver_application_server_for_java:7.50:*:*:*:*:*:*:*

14 Mar 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-14 05:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-27268

Mitre link : CVE-2023-27268

CVE.ORG link : CVE-2023-27268


JSON object : View

Products Affected

sap

  • netweaver_application_server_for_java
CWE
CWE-284

Improper Access Control