CVE-2023-50422
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 12, 2023
Updated: Jan 9, 2024
CWE ID 269
Summary
CVE-2023-50422 is a privileges escalation vulnerability affecting SAP BTP Security Services Integration Library, specifically versions below 2.17.0 and versions from 3.0.0 to before 3.3.0. An attacker, who is not authenticated, can exploit this issue under certain conditions and gain arbitrary permissions within the application. This vulnerability poses a significant risk, allowing unauthorized access and potential data breaches. It is crucial that affected organizations apply the necessary patches or workarounds to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- SAP SE