First published: Tue Jul 11 2023(Updated: )
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Process Integration | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-35873.
The severity of CVE-2023-35873 is medium with a CVSS score of 6.5.
SAP NetWeaver Process Integration version 7.50 is affected by CVE-2023-35873.
An unauthenticated user could access technical data and configuration information of the product.
Apply the necessary patches or updates provided by SAP to remediate CVE-2023-35873.