CVE-2023-39436: Information Disclosure in SAP Supplier Relationship Management
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39436?
The severity of CVE-2023-39436 is medium with a severity value of 5.8.
How can an unauthorized attacker exploit CVE-2023-39436?
An unauthorized attacker can exploit CVE-2023-39436 by discovering information related to SRM within Vendor Master Data for Business Partners replication functionality.
Which versions of SAP Supplier Relationship Management are affected by CVE-2023-39436?
Versions 600, 602, 603, 604, 605, 606, 616, and 617 of SAP Supplier Relationship Management are affected by CVE-2023-39436.
Is there a fix available for CVE-2023-39436?
Yes, you can find the fix for CVE-2023-39436 in the SAP notes available at https://me.sap.com/notes/2067220.
Where can I find more information about CVE-2023-39436?
You can find more information about CVE-2023-39436 in the document provided by SAP at https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html.