CVE-2023-29108: IP filter vulnerability in ABAP Platform and SAP Web Dispatcher
Published Apr 11, 2023
·Updated
The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources.
Affected Software
5 affected components
SAP ABAP Platform Kernel=7.85
SAP ABAP Platform Kernel=7.89
SAP ABAP Platform Kernel=7.91
SAP Web Dispatcher=7.85
SAP Web Dispatcher=7.89
Event History
Apr 11, 2023
CVE Published
via MITRE·02:56 AM
Data Sourced
via MITRE·02:56 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-29108.
2
What is the severity of CVE-2023-29108?
The severity of CVE-2023-29108 is medium with a severity value of 5.3.
3
Which software versions are affected by CVE-2023-29108?
The ABAP Platform versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, and SAP Web Dispatcher versions 7.85, 7.89 are affected by CVE-2023-29108.
4
What is the impact of CVE-2023-29108?
CVE-2023-29108 may enable access to backend applications from unwanted sources.
5
How can I fix CVE-2023-29108?
To fix CVE-2023-29108, apply the necessary patches and updates provided by SAP.