CVE-2023-28763

Severity
6.5MEDIUM
EPSS
0.5%
top 32.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11

Description

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-9j88-8w42-xmxg: SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-adm2023-04-11
CVEList
Denial of Service in SAP NetWeaver AS for ABAP and ABAP Platform2023-04-11
CVE-2023-28763 (MEDIUM CVSS 6.5) | SAP NetWeaver AS for ABAP and ABAP | cvebase.io