CVE-2023-35874: Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform
SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities that require user identity. An attacker can perform malicious actions over the network, extending the scope of impact, causing a limited impact on confidentiality, integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35874.
What is the severity of CVE-2023-35874?
The severity of CVE-2023-35874 is high with a CVSS score of 7.4.
Which software versions are affected by CVE-2023-35874?
SAP NetWeaver Application Server ABAP and ABAP Platform versions KRNL64NUC 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93 are affected by CVE-2023-35874.
How can I fix CVE-2023-35874 vulnerability?
To fix CVE-2023-35874 vulnerability, apply the necessary patch or software update provided by SAP.
Where can I find more information about CVE-2023-35874?
You can find more information about CVE-2023-35874 at the following references: [Reference 1](https://me.sap.com/notes/3318850), [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html)