CVE-2023-0014
published 2023-01-10CVE-2023-0014: SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.69%
49.1th percentile
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
| sap | netweaver_abap_server_and_abap_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44h8-4xm9-fmpv: SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNE
ghsa_unreviewed·2023-01-10
CVE-2023-0014 [CRITICAL] CWE-294 GHSA-44h8-4xm9-fmpv: SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNE
SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.
VMware
VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
vendor_vmware·2023-06-22·CVSS 8.1
CVE-2023-20892 [HIGH] VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
VMSA-2023-0014: VMware vCenter Server updates address multiple memory corruption vulnerabilities (CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896)
VMware Cloud Foundation VMware Cloud Foundation VMware vCenter Server
CVEs: CVE-2023-20892, CVE-2023-20893, CVE-2023-20894, CVE-2023-20895, CVE-2023-20896
Affected products: VMware Cloud Foundation, VMware vCenter Server, vSphere
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-10
Published