CVE Vulnerabilities

CVE-2023-0014

Authentication Bypass by Capture-replay

Published: Jan 10, 2023 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

Weakness

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Affected Software

Name Vendor Start Version End Version
Netweaver_application_server_abap Sap 700 (including) 700 (including)
Netweaver_application_server_abap Sap 701 (including) 701 (including)
Netweaver_application_server_abap Sap 702 (including) 702 (including)
Netweaver_application_server_abap Sap 710 (including) 710 (including)
Netweaver_application_server_abap Sap 711 (including) 711 (including)
Netweaver_application_server_abap Sap 730 (including) 730 (including)
Netweaver_application_server_abap Sap 731 (including) 731 (including)
Netweaver_application_server_abap Sap 740 (including) 740 (including)
Netweaver_application_server_abap Sap 750 (including) 750 (including)
Netweaver_application_server_abap Sap 751 (including) 751 (including)
Netweaver_application_server_abap Sap 752 (including) 752 (including)
Netweaver_application_server_abap Sap 753 (including) 753 (including)
Netweaver_application_server_abap Sap 754 (including) 754 (including)
Netweaver_application_server_abap Sap 755 (including) 755 (including)
Netweaver_application_server_abap Sap 756 (including) 756 (including)
Netweaver_application_server_abap Sap 757 (including) 757 (including)
Netweaver_application_server_abap_kernel Sap 7.22 (including) 7.22 (including)
Netweaver_application_server_abap_kernel Sap 7.53 (including) 7.53 (including)
Netweaver_application_server_abap_kernel Sap 7.77 (including) 7.77 (including)
Netweaver_application_server_abap_kernel Sap 7.81 (including) 7.81 (including)
Netweaver_application_server_abap_kernel Sap 7.85 (including) 7.85 (including)
Netweaver_application_server_abap_kernel Sap 7.89 (including) 7.89 (including)
Netweaver_application_server_abap_krnl64nuc Sap 7.22 (including) 7.22 (including)
Netweaver_application_server_abap_krnl64nuc Sap 7.22ext (including) 7.22ext (including)
Netweaver_application_server_abap_krnl64uc Sap 7.22 (including) 7.22 (including)
Netweaver_application_server_abap_krnl64uc Sap 7.22ext (including) 7.22ext (including)
Netweaver_application_server_abap_krnl64uc Sap 7.53 (including) 7.53 (including)

Potential Mitigations

References