CVE-2023-41366
Last modified
CVE-2023-41366 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application. . EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | kernel_7.22 |
| Sap | Netweaver Application Server Abap | kernel_7.53 |
| Sap | Netweaver Application Server Abap | kernel_7.54 |
| Sap | Netweaver Application Server Abap | kernel_7.77 |
| Sap | Netweaver Application Server Abap | kernel_7.85 |
| Sap | Netweaver Application Server Abap | kernel_7.89 |
| Sap | Netweaver Application Server Abap | kernel_7.91 |
| Sap | Netweaver Application Server Abap | kernel_7.92 |
| Sap | Netweaver Application Server Abap | kernel_7.93 |
| Sap | Netweaver Application Server Abap | kernel_7.94 |
| Sap | Netweaver Application Server Abap | kernel64nuc_7.22 |
| Sap | Netweaver Application Server Abap | kernel64nuc_7.22ext |
| Sap | Netweaver Application Server Abap | kernel64uc_7.22 |
| Sap | Netweaver Application Server Abap | kernel64uc_7.22ext |
| Sap | Netweaver Application Server Abap | kernel64uc_7.53 |
References
- https://me.sap.com/notes/3362849Permissions Required
- https://me.sap.com/notes/3362849Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41366?
How severe is CVE-2023-41366?
How do I fix CVE-2023-41366?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41360An issue was discovered in FRRouting FRR through 9.0. bgpd/b…9.1
- CVE-2023-41361An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.…9.8
- CVE-2023-41362MyBB before 1.8.36 allows Code Injection by users with certa…7.2
- CVE-2023-41363In Cerebrate 1.14, a vulnerability in UserSettingsController…4.3
- CVE-2023-41364In tine through 2023.01.14.325, the sort parameter of the /i…9.8
- CVE-2023-41365SAP Business One (B1i) - version 10.0, allows an authorized …4.3
- CVE-2023-41367Due to missing authentication check in webdynpro application…5.3
- CVE-2023-41368The OData service of the S4 HANA (Manage checkbook apps) - v…5.3
- CVE-2023-41369The Create Single Payment application of SAP S/4HANA - versi…4.3
- CVE-2023-41372The vulnerability allows an unprivileged (untrusted) third- …7.8
- CVE-2023-41373 A directory traversal vulnerability exists in the BIG-IP Co…9.9
- CVE-2023-41374Double free issue exists in Kostac PLC Programming Software …7.8
Are you affected by CVE-2023-41366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
