CVE-2023-50423
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 12, 2023
Updated: Dec 15, 2023
CWE ID 269
Summary
CVE-2023-50423 is a vulnerability affecting SAP BTP Security Services Integration Library in versions below 4.1.0. This issue permits an unauthenticated attacker to escalate privileges under specific conditions. Successful exploitation grants arbitrary permissions within the application, posing a significant security risk. Python's sap-xssec library is the affected component. Organizations running vulnerable versions must apply the necessary patches or updates to mitigate this escalation of privilege vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- SAP SE