CVE-2023-42477: Server-Side Request Forgery in SAP NetWeaver AS Java (GRMG Heartbeat application)
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-42477.
What is the affected software?
The affected software is SAP NetWeaver AS Java (GRMG Heartbeat application) version 7.50.
What is the severity of CVE-2023-42477?
The severity of CVE-2023-42477 is medium with a severity value of 6.5.
How can an attacker exploit CVE-2023-42477?
An attacker can exploit CVE-2023-42477 by sending a crafted request from a vulnerable web application.
Are there any references for CVE-2023-42477?
Yes, you can find references for CVE-2023-42477 at the following links: [https://me.sap.com/notes/3333426](https://me.sap.com/notes/3333426) and [https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).