CVE-2023-0014: Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
SAP NetWeaver ABAP Server and ABAP Platform - versions SAPBASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0014?
The severity of CVE-2023-0014 is critical with a score of 9.8.
What versions of SAP NetWeaver ABAP Server and ABAP Platform are affected by CVE-2023-0014?
Versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, and 7.22EXT are affected by CVE-2023-0014.
What is the description of CVE-2023-0014?
CVE-2023-0014 creates information about system identity in an ambiguous manner in SAP NetWeaver ABAP Server and ABAP Platform.
Where can I find more information about CVE-2023-0014?
You can find more information about CVE-2023-0014 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/3089413), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).
What is the CWE category of CVE-2023-0014?
The CWE category of CVE-2023-0014 is CWE-294.