CVE-2023-27270: Denial of Service (DoS) in SAP NetWeaver AS for ABAP and ABAP Platform
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources sufficiently to make it unavailable. There is no ability to view or modify any information.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27270.
What is the severity of CVE-2023-27270?
CVE-2023-27270 has a severity rating of 6.5 (medium).
Which versions of SAP NetWeaver Application Server for ABAP and ABAP Platform are affected by CVE-2023-27270?
Versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, and 791 of SAP NetWeaver Application Server for ABAP and ABAP Platform are affected by CVE-2023-27270.
What is the impact of CVE-2023-27270?
CVE-2023-27270 allows an attacker authenticated as a non-administrative user to craft a request with certain parameters, leading to multiple vulnerabilities in a class for test purposes.
Are there any fixes available for CVE-2023-27270?
Yes, SAP has provided fixes for CVE-2023-27270. Please refer to the official SAP support page and documentation for more information.