CVE Vulnerabilities

CVE-2023-28763

Published: Apr 11, 2023 | Modified: Apr 14, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the servers resources sufficiently to make it unavailable over the network without any user interaction.

Affected Software

Name Vendor Start Version End Version
Netweaver_application_server_abap Sap 740 740
Netweaver_application_server_abap Sap 750 750
Netweaver_application_server_abap Sap 751 751
Netweaver_application_server_abap Sap 752 752
Netweaver_application_server_abap Sap 753 753
Netweaver_application_server_abap Sap 754 754
Netweaver_application_server_abap Sap 755 755
Netweaver_application_server_abap Sap 756 756
Netweaver_application_server_abap Sap 757 757
Netweaver_application_server_abap Sap 791 791

References