cbcvebase.
CVE-2023-29108
published 2023-04-11

CVE-2023-29108: The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.42%
33.9th percentile
The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources.

Affected

10 ranges
VendorProductVersion rangeFixed in
sapabap_platform_and_sap_web_dispatcher
sapabap_platform_and_sap_web_dispatcher
sapabap_platform_and_sap_web_dispatcher
sapabap_platform_and_sap_web_dispatcher
sapabap_platform_and_sap_web_dispatcher
sapabap_platform_kernel
sapabap_platform_kernel
sapabap_platform_kernel
sapweb_dispatcher
sapweb_dispatcher
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.