CVE-2023-0016
published 2023-01-10CVE-2023-0016: SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.62%
45.4th percentile
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | business_planning_and_consolidation | — | — |
| sap | business_planning_and_consolidation | — | — |
| sap | sap_bpc_ms_10.0 | — | — |
| sap | sap_bpc_ms_10.0 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qv4h-7vx6-66cj: SAP BPC MS 10
ghsa_unreviewed·2023-01-10
CVE-2023-0016 [HIGH] CWE-89 GHSA-qv4h-7vx6-66cj: SAP BPC MS 10
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.
VMware
VMware Tanzu Application Service for VMs and Isolation Segment updates address information disclosure vulnerability (CVE-2023-20891)
vendor_vmware·2023-07-25·CVSS 6.5
CVE-2023-20891 [MEDIUM] VMware Tanzu Application Service for VMs and Isolation Segment updates address information disclosure vulnerability (CVE-2023-20891)
VMSA-2023-0016: VMware Tanzu Application Service for VMs and Isolation Segment updates address information disclosure vulnerability (CVE-2023-20891)
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs .VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.5.
CVEs: CVE-2023-20891
Affected products: VMware Tanzu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-10
Published