CVE-2023-37491
Last modified
CVE-2023-37491 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server. This may lead to unauthorized read and write of data as well as rendering the system unavailable.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server. This may lead to unauthorized read and write of data as well as rendering the system unavailable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Message Server | kernel_7.22 |
| Sap | Message Server | kernel_7.53 |
| Sap | Message Server | kernel_7.54 |
| Sap | Message Server | kernel_7.77 |
| Sap | Message Server | krnl64nuc_7.22 |
| Sap | Message Server | krnl64nuc_7.22ex |
| Sap | Message Server | rnl64uc_7.22 |
| Sap | Message Server | rnl64uc_7.22ext |
| Sap | Message Server | rnl64uc_7.53 |
References
- https://me.sap.com/notes/3344295Permissions Required
- https://me.sap.com/notes/3344295Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37491?
How severe is CVE-2023-37491?
How do I fix CVE-2023-37491?
Are you affected by CVE-2023-37491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
