CVE Vulnerabilities

CVE-2023-35874

Improper Authentication

Published: Jul 11, 2023 | Modified: Jul 19, 2023
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities that require user identity. An attacker can perform malicious actions over the network, extending the scope of impact, causing a limited impact on confidentiality, integrity and availability.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Netweaver_application_server_abap Sap kernel_7.22 (including) kernel_7.22 (including)
Netweaver_application_server_abap Sap kernel_7.53 (including) kernel_7.53 (including)
Netweaver_application_server_abap Sap kernel_7.54 (including) kernel_7.54 (including)
Netweaver_application_server_abap Sap kernel_7.77 (including) kernel_7.77 (including)
Netweaver_application_server_abap Sap kernel_7.81 (including) kernel_7.81 (including)
Netweaver_application_server_abap Sap kernel_7.85 (including) kernel_7.85 (including)
Netweaver_application_server_abap Sap kernel_7.89 (including) kernel_7.89 (including)
Netweaver_application_server_abap Sap kernel_7.92 (including) kernel_7.92 (including)
Netweaver_application_server_abap Sap kernel_7.93 (including) kernel_7.93 (including)
Netweaver_application_server_abap Sap krnl64nuc_7.22 (including) krnl64nuc_7.22 (including)
Netweaver_application_server_abap Sap krnl64nuc_7.22ext (including) krnl64nuc_7.22ext (including)
Netweaver_application_server_abap Sap krnl64uc_7.22 (including) krnl64uc_7.22 (including)
Netweaver_application_server_abap Sap krnl64uc_7.22ext (including) krnl64uc_7.22ext (including)
Netweaver_application_server_abap Sap krnl64uc_7.53 (including) krnl64uc_7.53 (including)

Potential Mitigations

References