Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27897

Опубликовано: 11 апр. 2023
Источник: nvd
CVSS3: 6
CVSS3: 6.3
EPSS Низкий

Описание

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:customer_relationship_management:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management:712:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management:713:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02251
Низкий

6 Medium

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.3
github
почти 3 года назад

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

EPSS

Процентиль: 84%
0.02251
Низкий

6 Medium

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-94