CVE-2023-0025: XSS
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0025?
CVE-2023-0025 is a vulnerability in SAP Solution Manager (BSP Application) version 720 that allows an authenticated attacker to craft a malicious link to read or modify sensitive information or restrict access to resources.
What is the severity of CVE-2023-0025?
The severity of CVE-2023-0025 is medium, with a severity value of 5.4 on the CVSS scale.
How does CVE-2023-0025 affect SAP Solution Manager?
CVE-2023-0025 affects SAP Solution Manager version 720, allowing an authenticated attacker to craft a malicious link that can be used to exploit the vulnerability.
How can an attacker exploit CVE-2023-0025?
An attacker can exploit CVE-2023-0025 by crafting a malicious link and tricking an unsuspecting user into clicking on it, which can lead to unauthorized access or modification of sensitive information.
Is there a fix for CVE-2023-0025?
Yes, SAP has released security notes and patches to address the vulnerability. It is recommended to apply the necessary updates as soon as possible.