Логотип exploitDog
bind:CVE-2023-40309
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-40309

Количество 3

Количество 3

nvd логотип

CVE-2023-40309

больше 2 лет назад

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42qx-rv8j-r8f3

больше 2 лет назад

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-07391

больше 2 лет назад

Уязвимость библиотеки SAP CommonCryptoLib, связанная с недостатками процедуры авторизации, позволяющая нарушителю читать, изменять или удалять данные с ограниченным доступом

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-40309

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42qx-rv8j-r8f3

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-07391

Уязвимость библиотеки SAP CommonCryptoLib, связанная с недостатками процедуры авторизации, позволяющая нарушителю читать, изменять или удалять данные с ограниченным доступом

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу