CVE-2023-49584: Client-Side Desynchronization vulnerability in SAP Fiori Launchpad

Published Dec 12, 2023
·
Updated

SAP Fiori launchpad - versions SAPUI 750, SAPUI 754, SAPUI 755, SAPUI 756, SAPUI 757, SAPUI 758, UI700 200, SAPBASIS 793, allows an attacker to use HTTP verb POST on read-only service causing low impact on Confidentiality of the application.

Affected Software

9 affected components
SAP Fiori Launchpad=200
SAP Fiori Launchpad=700
SAP Fiori Launchpad=750
SAP Fiori Launchpad=754
SAP Fiori Launchpad=755
SAP Fiori Launchpad=756
SAP Fiori Launchpad=757
SAP Fiori Launchpad=758
SAP Fiori Launchpad=793

Event History

Dec 12, 2023
CVE Published
01:35 AM
Data Sourced
01:35 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2023-49584?

CVE-2023-49584 is classified as low impact on the confidentiality of the application.

2

How do I fix CVE-2023-49584?

To remediate CVE-2023-49584, update to the latest version of SAP Fiori launchpad that addresses this vulnerability.

3

Which SAP Fiori launchpad versions are affected by CVE-2023-49584?

CVE-2023-49584 affects SAP Fiori launchpad versions 750, 754, 755, 756, 757, 758, and that is associated with UI version 700 as well as SAP_BASIS version 793.

4

What type of attack can CVE-2023-49584 enable?

CVE-2023-49584 allows attackers to make POST requests on read-only services, which could lead to unauthorized data exposure.

5

Is CVE-2023-49584 a concern for all SAP Fiori launchpad versions?

CVE-2023-49584 is a concern specifically for the specified vulnerable versions of SAP Fiori launchpad and does not impact all versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203