cbcvebase.
CVE-2023-23854
published 2023-02-14

CVE-2023-23854: SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks…

PriorityP427medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.46%
37.0th percentile
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Affected

16 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
sapnetweaver_as_abap_and_abap_platform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.