CVE-2023-49583: Escalation of Privileges in SAP BTP Security Services Integration Library ([Node.js] @sap/xssec)
SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49583?
CVE-2023-49583 is classified as a critical vulnerability due to the potential for privilege escalation.
How do I fix CVE-2023-49583?
To fix CVE-2023-49583, update the @sap/xssec package to version 3.6.0 or higher.
What applications are affected by CVE-2023-49583?
CVE-2023-49583 affects applications that utilize versions of the @sap/xssec library prior to 3.6.0.
Can CVE-2023-49583 be exploited by authenticated users?
CVE-2023-49583 can be exploited by unauthenticated attackers, allowing access to arbitrary permissions.
What are the implications of CVE-2023-49583 exploitation?
Exploitation of CVE-2023-49583 could allow attackers to gain elevated privileges and perform unauthorized actions within the application.