CVE-2023-26459: Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26459?
The severity of CVE-2023-26459 is high with a severity value of 7.4.
How can an attacker exploit CVE-2023-26459?
An attacker authenticated as a non-administrative user can exploit CVE-2023-26459 by crafting a request to trigger the application server.
Which versions of SAP NetWeaver AS for ABAP and ABAP Platform are affected by CVE-2023-26459?
The versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, and 791 of SAP NetWeaver AS for ABAP and ABAP Platform are affected by CVE-2023-26459.
How can I fix CVE-2023-26459?
To fix CVE-2023-26459, it is recommended to apply the necessary patches provided by SAP.
Where can I find more information about CVE-2023-26459?
You can find more information about CVE-2023-26459 in the SAP Note 3296346 and the SAP document.