SB2023080132 - MitM attack in SAP Plant Connectivity



SB2023080132 - MitM attack in SAP Plant Connectivity

Published: August 1, 2023

Security Bulletin ID SB2023080132
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2023-2827)

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to improper verification of cryptographic signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. A remote attacker can perform MitM attack.


Remediation

Install update from vendor's website.