CVE-2023-0013
published 2023-01-10CVE-2023-0013: The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.36%
27.8th percentile
The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
| sap | netweaver_as_for_abap_and_abap_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cisa3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chrg-5xr2-ppfm: The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP
ghsa_unreviewed·2023-01-10
CVE-2023-0013 [MEDIUM] CWE-79 GHSA-chrg-5xr2-ppfm: The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP
The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
CISA
VMware Tools Authentication Bypass Vulnerability
cisa·2023-06-23·CVSS 3.9
CVE-2023-20867 [LOW] CWE-287 VMware Tools Authentication Bypass Vulnerability
Vulnerability: VMware Tools Authentication Bypass Vulnerability
Affected: VMware Tools
VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
Required Action: Apply updates per vendor instructions.
Notes: https://www.vmware.com/security/advisories/VMSA-2023-0013.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20867
Remediation Due Date: 2023-07-14
VMware
VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
vendor_vmware·2023-06-13·CVSS 3.9
CVE-2023-20867 [LOW] VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
VMSA-2023-0013: VMware Tools update addresses Authentication Bypass vulnerability (CVE-2023-20867)
VMware Tools contains an Authentication Bypass vulnerability in the vgauth module. VMware has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3 base score of 3.9.
CVEs: CVE-2023-20867
Affected products: ESXi, VMware Tools, vSphere
No detection rules found.
Nuclei
SuperWebMailer - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2023-38194 [MEDIUM] SuperWebMailer - Cross-Site Scripting
SuperWebMailer - Cross-Site Scripting
An issue was discovered in SuperWebMailer 9.00.0.01710 that allows keepalive.php XSS via a GET parameter.
Template:
id: CVE-2023-38194
info:
name: SuperWebMailer - Cross-Site Scripting
author: ritikchaddha
severity: medium
description: |
An issue was discovered in SuperWebMailer 9.00.0.01710 that allows keepalive.php XSS via a GET parameter.
impact: |
Successful exploitation could allow an attacker to execute malicious scripts in the context of a user's browser, leading to potential data theft or account compromise.
remediation: |
Implement input validation and output encoding to prevent XSS attacks in the SuperWebMailer keepalive.php script.
reference:
- https://herolab.usd.de/security-advisories/usd-2023-0013/
- https://nvd.nist.gov/vuln/detail/C
No writeups or analysis indexed.
2023-01-10
Published