CVE-2023-0021

CVSS V2 None CVSS V3 None
Description
Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could lead to reflected Cross-Site scripting. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.
Overview
  • CVE ID
  • CVE-2023-0021
  • Assigner
  • cna@sap.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-14T05:15:28
  • Last Modified Date
  • 2023-03-16T19:07:28
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:sap:netweaver:700:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:netweaver:701:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:netweaver:702:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:netweaver:731:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:netweaver:740:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:sap:netweaver:750:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 06:22:49 Added to TrackCVE
2023-04-17 06:22:52 Weakness Enumeration new