CVE-2023-31405: Log Injection vulnerability in SAP NetWeaver AS for Java (Log Viewer)
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31405?
The severity of CVE-2023-31405 is medium with a CVSS score of 5.3.
How does CVE-2023-31405 affect SAP NetWeaver AS for Java?
CVE-2023-31405 affects SAP NetWeaver AS for Java versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50.
What can an unauthenticated attacker do with CVE-2023-31405?
An unauthenticated attacker can craft a request over the network that can result in unwarranted modifications to a system log without user interaction.
How can I view more information about CVE-2023-31405?
You can view more information about CVE-2023-31405 at the following references: [Reference 1](https://me.sap.com/notes/3324732), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).
How do I fix CVE-2023-31405?
To fix CVE-2023-31405, you should apply the necessary security patches or updates provided by SAP.