CVE Database
/

CVE-2023-49580

Back to search

CVE-2023-49580

Published: Dec 12, 2023

Modified: Sep 28, 2024

PUBLISHED

CVSS v3.1

7.3

HIGH

Description

SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to create Layout configurations of the ABAP List Viewer and with this causing a mild impact on integrity and availability, e.g. also increasing the response times of the AS ABAP.

VendorProductVersions

SAP_SE

SAP GUI for Windows and SAP GUI for Java

affected
SAP_BASIS 755
affected
SAP_BASIS 756
affected
SAP_BASIS 757
affected
SAP_BASIS 758

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2023-49580 | HIGH (7.3) - Security Vulnerability | QwikSec