First published: Tue Nov 14 2023(Updated: )
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server ABAP | =kernel_7.22 | |
SAP NetWeaver Application Server ABAP | =kernel_7.53 | |
SAP NetWeaver Application Server ABAP | =kernel_7.54 | |
SAP NetWeaver Application Server ABAP | =kernel_7.77 | |
SAP NetWeaver Application Server ABAP | =kernel_7.85 | |
SAP NetWeaver Application Server ABAP | =kernel_7.89 | |
SAP NetWeaver Application Server ABAP | =kernel_7.91 | |
SAP NetWeaver Application Server ABAP | =kernel_7.92 | |
SAP NetWeaver Application Server ABAP | =kernel_7.93 | |
SAP NetWeaver Application Server ABAP | =kernel_7.94 | |
SAP NetWeaver Application Server ABAP | =kernel64nuc_7.22 | |
SAP NetWeaver Application Server ABAP | =kernel64nuc_7.22ext | |
SAP NetWeaver Application Server ABAP | =kernel64uc_7.22 | |
SAP NetWeaver Application Server ABAP | =kernel64uc_7.22ext | |
SAP NetWeaver Application Server ABAP | =kernel64uc_7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41366 is an information disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform.
The affected versions are KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT.
The severity of CVE-2023-41366 is medium with a CVSS score of 5.3.
To fix CVE-2023-41366, apply the necessary patches provided by SAP.
You can find more information about CVE-2023-41366 in SAP Note 3362849 and the official SAP document.