CVE-2023-41366: Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT, allows an unauthenticated attacker to access the unintended data due to the lack of restrictions applied which may lead to low impact in confidentiality and no impact on the integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41366?
CVE-2023-41366 is an information disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform.
What versions of SAP NetWeaver Application Server ABAP are affected by CVE-2023-41366?
The affected versions are KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, KERNEL64UC 7.22EXT, KERNEL64UC 7.53, KERNEL64NUC 7.22, KERNEL64NUC 7.22EXT.
What is the severity of CVE-2023-41366?
The severity of CVE-2023-41366 is medium with a CVSS score of 5.3.
How can I fix CVE-2023-41366?
To fix CVE-2023-41366, apply the necessary patches provided by SAP.
Where can I find more information about CVE-2023-41366?
You can find more information about CVE-2023-41366 in SAP Note 3362849 and the official SAP document.