CVE-2023-23854: Medium severity sap netweaver as abap vulnerability
Published Feb 14, 2023
·Updated
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Affected Software
8 affected components
SAP NetWeaver Application Server ABAP=700
SAP NetWeaver Application Server ABAP=701
SAP NetWeaver Application Server ABAP=702
SAP NetWeaver Application Server ABAP=731
SAP NetWeaver Application Server ABAP=740
SAP NetWeaver Application Server ABAP=750
SAP NetWeaver Application Server ABAP=751
SAP NetWeaver Application Server ABAP=752
Event History
Feb 14, 2023
CVE Published
via MITRE·03:13 AM
Data Sourced
via MITRE·03:13 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23854.
2
What is the severity of CVE-2023-23854?
The severity of CVE-2023-23854 is medium.
3
Which SAP NetWeaver Application Server versions are affected by CVE-2023-23854?
SAP NetWeaver Application Server versions 700, 701, 702, 731, 740, 750, 751, and 752 are affected by CVE-2023-23854.
4
What is the impact of CVE-2023-23854?
CVE-2023-23854 allows an authenticated user to escalate their privileges.
5
Are there any references for CVE-2023-23854?
Yes, you can find references for CVE-2023-23854 at the following links: [link1](https://launchpad.support.sap.com/#/notes/3287291) and [link2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).