CVE-2023-23859: XSS
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23859?
The severity of CVE-2023-23859 is medium.
How can an attacker exploit CVE-2023-23859?
An unauthenticated attacker can exploit CVE-2023-23859 by crafting a malicious link and tricking an unsuspecting user into clicking on it.
Which versions of SAP NetWeaver AS for ABAP and ABAP Platform are affected by CVE-2023-23859?
Versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790 of SAP NetWeaver AS for ABAP and ABAP Platform are affected by CVE-2023-23859.
What can an attacker do if they successfully exploit CVE-2023-23859?
If an attacker successfully exploits CVE-2023-23859, they can read or modify some sensitive information.
Where can I find more information about CVE-2023-23859?
You can find more information about CVE-2023-23859 at the following references: [Reference 1](https://launchpad.support.sap.com/#/notes/3268959) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).