CVE Vulnerabilities

CVE-2023-26459

Server-Side Request Forgery (SSRF)

Published: Mar 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

NameVendorStart VersionEnd Version
Netweaver_application_server_abapSap700 (including)700 (including)
Netweaver_application_server_abapSap701 (including)701 (including)
Netweaver_application_server_abapSap702 (including)702 (including)
Netweaver_application_server_abapSap731 (including)731 (including)
Netweaver_application_server_abapSap740 (including)740 (including)
Netweaver_application_server_abapSap750 (including)750 (including)
Netweaver_application_server_abapSap751 (including)751 (including)
Netweaver_application_server_abapSap752 (including)752 (including)
Netweaver_application_server_abapSap753 (including)753 (including)
Netweaver_application_server_abapSap754 (including)754 (including)
Netweaver_application_server_abapSap755 (including)755 (including)
Netweaver_application_server_abapSap756 (including)756 (including)
Netweaver_application_server_abapSap757 (including)757 (including)
Netweaver_application_server_abapSap791 (including)791 (including)

References