CVE-2023-49578: Denial of service (DOS) in SAP Cloud Connector
Published Dec 12, 2023
·Updated
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integrity of the application.
Affected Software
1 affected component
SAP Cloud Connector=2.0
Event History
Dec 12, 2023
CVE Published
via MITRE·01:08 AM
Data Sourced
via MITRE·01:08 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49578?
CVE-2023-49578 is classified as low severity due to its limited impact on availability.
2
How do I fix CVE-2023-49578?
To mitigate CVE-2023-49578, ensure that your SAP Cloud Connector is updated to the latest version.
3
Who is affected by CVE-2023-49578?
CVE-2023-49578 affects users of SAP Cloud Connector version 2.0.
4
What type of attack does CVE-2023-49578 facilitate?
CVE-2023-49578 allows for a Denial of Service attack to be performed by an authenticated user.
5
What is the potential impact of CVE-2023-49578?
The potential impact of CVE-2023-49578 is low, affecting only the availability of the application.