First published: Tue Oct 10 2023(Updated: )
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server Java | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-42477.
The affected software is SAP NetWeaver AS Java (GRMG Heartbeat application) version 7.50.
The severity of CVE-2023-42477 is medium with a severity value of 6.5.
An attacker can exploit CVE-2023-42477 by sending a crafted request from a vulnerable web application.
Yes, you can find references for CVE-2023-42477 at the following links: [https://me.sap.com/notes/3333426](https://me.sap.com/notes/3333426) and [https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).