CVE-2023-49584: Client-Side Desynchronization vulnerability in SAP Fiori Launchpad
SAP Fiori launchpad - versions SAPUI 750, SAPUI 754, SAPUI 755, SAPUI 756, SAPUI 757, SAPUI 758, UI700 200, SAPBASIS 793, allows an attacker to use HTTP verb POST on read-only service causing low impact on Confidentiality of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49584?
CVE-2023-49584 is classified as low impact on the confidentiality of the application.
How do I fix CVE-2023-49584?
To remediate CVE-2023-49584, update to the latest version of SAP Fiori launchpad that addresses this vulnerability.
Which SAP Fiori launchpad versions are affected by CVE-2023-49584?
CVE-2023-49584 affects SAP Fiori launchpad versions 750, 754, 755, 756, 757, 758, and that is associated with UI version 700 as well as SAP_BASIS version 793.
What type of attack can CVE-2023-49584 enable?
CVE-2023-49584 allows attackers to make POST requests on read-only services, which could lead to unauthorized data exposure.
Is CVE-2023-49584 a concern for all SAP Fiori launchpad versions?
CVE-2023-49584 is a concern specifically for the specified vulnerable versions of SAP Fiori launchpad and does not impact all versions.