cbcvebase.
CVE-2023-27897
published 2023-04-11

CVE-2023-27897: In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can…

PriorityP338medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.65%
47.1th percentile
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

Affected

10 ranges
VendorProductVersion rangeFixed in
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcustomer_relationship_management
sapcustomer_relationship_management
sapcustomer_relationship_management
sapcustomer_relationship_management
sapcustomer_relationship_management
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.