CVE-2023-28761: Missing Authentication check in SAP NetWeaver Enterprise Portal
Published Apr 11, 2023
·Updated
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity.
Affected Software
1 affected component
SAP NetWeaver Enterprise Portal=7.50
Event History
Apr 11, 2023
CVE Published
via MITRE·02:51 AM
Data Sourced
via MITRE·02:51 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of this SAP NetWeaver Enterprise Portal vulnerability?
The vulnerability ID is CVE-2023-28761.
2
What is the severity rating of CVE-2023-28761?
CVE-2023-28761 has a severity rating of 6.5 (medium).
3
How does the vulnerability CVE-2023-28761 impact confidentiality and integrity?
The vulnerability can lead to limited impact on confidentiality and integrity.
4
Which version of SAP NetWeaver Enterprise Portal is affected by CVE-2023-28761?
Version 7.50 of SAP NetWeaver Enterprise Portal is affected.
5
Is authentication required for an attacker to exploit CVE-2023-28761?
No, an unauthenticated attacker can exploit this vulnerability.