CVE-2023-23851
published 2023-02-14CVE-2023-23851: SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.34%
26.6th percentile
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | business_planning_and_consolidation | — | — |
| sap | business_planning_and_consolidation | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmf8-wm54-9xq4: SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)
ghsa_unreviewed·2023-02-14
CVE-2023-23851 [MEDIUM] CWE-434 GHSA-rmf8-wm54-9xq4: SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their consent impacting the confidentiality and integrity of the system.
Red Hat
kernel: copy_params can attempt to allocate more than INT_MAX bytes and crash
vendor_redhat·2024-01-23·CVSS 5.5
CVE-2024-23851 [MEDIUM] kernel: copy_params can attempt to allocate more than INT_MAX bytes and crash
kernel: copy_params can attempt to allocate more than INT_MAX bytes and crash
copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. This is related to ctl_ioctl.
A vulnerability was found in copy_params in drivers/md/dm-ioctl.c in the Linux kernel, where it can attempt to allocate more than INT_MAX bytes and crash due to a missing param_kernel->data_size check. This issue is related to ctl_ioctl.
Statement: This flaw was found to be a duplicate of CVE-2023-52429. Please see https://access.redhat.com/security/cve/CVE-2023-52429 for information about affected products and security errata.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: ker
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published